The Pods plugin for WordPress, which allows for custom content types and fields, has a security vulnerability that could allow malicious code to be injected into pages. This could happen if an attacker with administrator-level access adds scripts through the plugin’s settings. This only affects certain types of installations and versions up to 3.2.7.