The NotificationX plugin for WordPress has a security issue that allows hackers to inject harmful code into web pages. This can happen because the plugin does not properly clean and protect the information it receives and displays. As a result, attackers with certain levels of access can insert their own code into pages, which will then run when users visit those pages.