A popular plugin for WordPress called “Product Carousel Slider & Grid Ultimate for WooCommerce” has a security issue that could allow hackers to insert harmful code into website pages. This vulnerability affects all versions up to 1.10.0 and is caused by not properly cleaning up user input. It can only be exploited by logged-in users with certain permissions and does not affect all WordPress websites.