The MailPoet Newsletters plugin for WordPress contains a security flaw. If you have version 2.7.2 or an earlier version of the plugin, attackers could inject malicious web scripts onto pages using the ‘encodedForm’ parameter. This would occur if they were able to trick a user into performing an action, such as clicking on a link. To protect yourself, make sure you’re using the latest version of the plugin.