The MultiVendorX Marketplace, a plugin for WordPress, has a security issue that allows hackers to inject harmful code into pages. This can be done by adding a parameter called ‘hover_animation’ and it affects all versions up to 4.1.11. This vulnerability is due to the plugin not properly filtering and protecting inputs and outputs. This means that anyone with Contributor-level access or higher can add code that will run whenever someone visits a page with the injected code.