The WordPress Pinterest Plugin for WordPress has a security vulnerability that can allow attackers to inject harmful code into pages. This can happen if the plugin’s shortcode is used in versions 1.8.2 and below. This can only be done by users who have contributor-level access or higher.