The Gutentor plugin for WordPress has a security issue in versions up to 3.4.1. This can allow attackers with contributor-level access or higher to insert harmful web scripts into pages. These scripts will run whenever a user visits the affected page.