The Mail Subscribe List plugin for WordPress is vulnerable to a security risk in versions up to and including 1.0.0. Attackers who are not authorized can inject web scripts in pages which will be run every time a user views the page. This happens because the plugin does not properly sanitize the data it receives, or properly escape the output.