A security vulnerability was recently reported in the Open Hours plugin by a third-party security researcher via Wordfence. The report outlines a Stored Cross-Site Scripting (XSS) vulnerability that affects all versions up to and including 1.0.9.
Internal Reference