A WordPress plugin called “Restrict User Access – Membership Plugin with Force” has a security issue that could allow hackers to inject harmful web scripts onto a website. This can happen if someone who is not logged in to the website clicks on a link that the hacker has created. The issue affects versions up to 2.5 of the plugin.