The YITH WooCommerce Multi Vendor plugin for WordPress has a security vulnerability in versions up to and including 3.8.0. This vulnerability makes it possible for attackers who are not logged in to the website to inject malicious code into pages on the website. This malicious code could be executed if a user were to click on a link that was sent by the attacker. This vulnerability can be avoided by updating to a version of the plugin that is not vulnerable to this issue.