The Ad Invalid Click Protector (AICP) WordPress plugin has a security vulnerability which allows malicious attackers to take control of it. Attackers can use the page parameter to inject malicious code known as Reflected Cross-Site Scripting. Additionally, they can also use Cross-Site Request Forgery to delete banned users.