The Social Warfare plugin for WordPress has a vulnerability that allows hackers to insert harmful code into web pages using the plugin’s ‘socialWarfare’ shortcode. This can happen in all versions up to 4.4.6.1 because the plugin does not properly filter and protect user input. This means that attackers with certain permissions can add their own code to pages, which will run when someone views that page.