The WP Project Manager plugin for WordPress has a security issue that allows hackers to insert harmful code into web pages using SVG files. This can happen because the plugin does not properly clean and protect the input and output of these files. As a result, attackers with Author-level access or higher can exploit this vulnerability and harm users who access the affected web pages.