The Post SMTP plugin used for WordPress has a security issue where hackers can insert harmful website code in pages by exploiting the “from” and “subject” parameters. This can be done by attackers who are not logged in, and it affects all versions up to 3.0.2. This could lead to the execution of unauthorized scripts when a user visits the affected page.