The WP User Frontend plugin for WordPress has a security issue that allows attackers to inject malicious code through the ‘orderby’ parameter. This can be done by users with administrator-level access or higher, and it can result in sensitive information being accessed from the database.