The click-to-top plugin for WordPress is not secure in versions up to and including 1.2.7. This means attackers can put malicious code on a web page that will run when a user visits that page. This is possible because the plugin does not properly check and filter data when it is put into the page or when it is outputted.