The WooCommerce Product Carousel, Slider & Grid Ultimate plugin for WordPress has a security vulnerability in versions up to and including 1.8.6. This vulnerability allows users with contributor or higher level access to insert malicious JavaScript into the database. This happens because the plugin does not properly sanitize user input when it is put into the database.