WordPress plugin hole puts ‘2 million websites’ at risk

WordPress users with the Advanced Custom Fields plugin on their website should upgrade after the discovery of a vulnerability in the code that could open up sites and their visitors to cross-site scripting (XSS) attacks.

You can read the full article here.