A plugin called Categorify for WordPress has a security issue that allows hackers to potentially add categories without permission. This affects all versions up to 1.0.7.4. The problem is caused by a lack of proper validation when using the categorifyAjaxAddCategory function. This means that if an attacker can trick a site administrator into clicking on a link, they can add categories to the website.