The PowerPress plugin for WordPress is vulnerable to a type of malicious code called Stored Cross-Site Scripting. This malicious code can be inserted into the plugin through the ‘Feed[title]’ parameter, and versions up to and including 10.2.3 are affected. This malicious code can be injected by attackers who have administrator-level permissions or higher. Whenever a user visits an infected page, the malicious code will execute.