The PPOM for WooCommerce plugin for WordPress is not secure in versions up to 32.0.6. Attackers can use certain query parameters to inject malicious code into pages which can then be executed if a user clicks on a link. This means that even unauthenticated attackers can take advantage of this vulnerability.