The Tripetto plugin for WordPress has a security issue that allows hackers to inject harmful code through file uploads. This can happen in any version up to 8.0.3 because the plugin does not properly clean or protect the input and output. This means that attackers who are not logged in can add their own code to files, and when someone views those files, the code will run.