A plugin called “Staff Directory” used for creating a company directory in WordPress has a security issue. This means that in versions up to 4.3, hackers can inject harmful code into the plugin and execute it when someone accesses it. This can happen even if the user is not logged in.