The ThemeREX Addons plugin for WordPress has a security issue that allows hackers to inject harmful code into websites. This is possible through the use of SVG files, a type of image file, in versions 2.35.1.1 and earlier. This occurs because the plugin does not properly check and filter the content of these files. As a result, attackers with certain levels of access can upload a malicious SVG file and have it execute harmful code whenever someone views the file on the website.