A popular WordPress plugin called “RSS Aggregator by Feedzy” has a security issue that allows hackers to inject harmful code into websites. This can happen when someone tries to access a page with an invalid RSS feed. The plugin hasn’t been updated to fix this issue, so it affects all versions up to 4.3.3. To make matters worse, only users with contributor-level access or higher can do this, which means they can cause damage without being detected easily.