The weForms add-on for WordPress has a security vulnerability that allows attackers to insert harmful scripts into web pages. This can happen when a user accesses a page that has been injected with these scripts. The vulnerability exists in all versions up to and including 1.6.21, as the input is not properly sanitized and the output is not properly escaped. This means that even users who are not logged in can exploit this vulnerability.