The WP Mail Logging plugin for WordPress is not secure in versions up to, and including, 1.11.0. This means that attackers who do not need to be logged in to the website can inject malicious scripts that will run when any user visits a page with the script. This is possible because the plugin does not properly check and protect the input and output of the website.