The Visualizer plugin for WordPress is not secure in versions up to 3.9.1. This means that people with contributor-level permissions can put malicious code into pages that will run when someone looks at them. This is because the plugin does not properly check the input or protect the output.