The Post SMTP Mailer/Email Log plugin for WordPress is not secure in versions up to and including 2.1.3. This means that people with administrative access and higher can inject malicious code into pages that will run automatically when someone visits the page. This is called Stored Cross-Site Scripting and it is caused by a lack of protection for user input and output.