The WP Plugin Info Card plugin for WordPress has a security vulnerability which can be exploited by unauthenticated attackers. This vulnerability allows attackers to inject malicious web scripts into pages that are visited by users if they click on a link. This vulnerability affects all versions of the plugin up to and including version 2.3.6, due to an issue with insufficient input sanitization and output escaping.