Cross-site scripting (XSS) vulnerability in the Markdown on Save Improved plugin before 2.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Referenceshttp://jvn.jp/en/jp/JVN26026353/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2016-000071https://srd.wordpress.org/plugins/markdown-on-save-improved/changelog/