The GDPR Cookie Consent plugin used for WordPress has a security vulnerability where attackers can insert harmful web scripts into pages without being authenticated. This is because the plugin does not properly clean and protect the input and output.