A popular WordPress plugin called “Popup Maker” has a security issue that allows attackers to insert harmful code into pop-up windows. This can happen because the plugin does not properly clean up or protect the information it receives from users. As a result, attackers with certain levels of access can add their own code to pop-ups, which can harm users who view them.