The Stackable plugin for WordPress has a security vulnerability that allows attackers to inject harmful scripts into pages. This can be done by using the Post(v2) block title tag, and it affects all versions up to 3.12.11. This means that anyone with contributor-level or higher permissions can potentially insert dangerous code that will run when someone views the affected page.