The WordPress Custom Settings plugin has a security issue that could allow someone with administrator-level access to add malicious code to pages. This malicious code could be run when other users view those pages. This only affects websites with multiple sites or websites where website code is not allowed. Versions up to and including 1.0 of the plugin are vulnerable and should be updated.