A popular plugin for WordPress called “Magical Posts Display” has a security vulnerability that allows hackers to inject harmful code into pages. This can happen when a user with certain permissions, like a contributor, accesses a page that has been targeted by the hacker.