The Paid Memberships Pro plugin for WordPress has a security vulnerability that allows someone to insert malicious code into pages on websites using the plugin. This code will then be run when someone visits the page. This vulnerability affects versions up to and including 2.5.9.1, as the plugin does not properly protect against malicious code being inserted into pages.