The Guest posting / Frontend Posting wordpress plugin, called WP Front User Submit / Front Editor plugin, has a security issue that could allow hackers to inject harmful code into a website. This can happen if the plugin is not properly sanitized and protected. The vulnerability affects all versions up to 4.4.1 and can only be exploited by users with high-level permissions. It mainly affects multi-site installations and those with unfiltered_html disabled.