The WC Marketplace plugin for WordPress has a security issue called Stored Cross-Site Scripting. This means that the plugin does not properly clean up the information it receives and sends out. As a result, attackers with contributor-level access or higher can insert harmful code into pages, which will run whenever someone opens that page.