The Social Warfare plugin for WordPress is vulnerable to a type of security threat called Stored Cross-Site Scripting. This means that on versions of the plugin prior to 4.4.3, attackers who have certain levels of permissions can inject malicious code into web pages. This code will then run when a user visits the page, allowing the attacker to take control of the user’s browser and access private data. To protect yourself, make sure you are always using the most recent version of the plugin.