Several plugins used on WordPress websites are at risk of a type of hacking called Stored Cross-Site Scripting. This happens because the plugins use a JavaScript library called FancyBox that is not properly protected against malicious code. As a result, attackers who have contributor-level access or higher can add their own harmful code to a webpage and trick users into running it when they visit that page.