The Visualizer plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. This means that if someone can trick a user into clicking on a link, they can inject their own web scripts into the page. This vulnerability affects versions of Visualizer up to and including 3.7.6.