The Levo Slideshow plugin for WordPress can be vulnerable to a problem called Stored Cross-Site Scripting. This is a security issue that affects versions of the plugin up to and including version 2.3. It happens because of a lack of proper input sanitization and output escaping. This means that attackers who have been authenticated, or given permission, can put in scripts that will be executed when someone visits the page.