A popular plugin for WordPress, called NotificationX, has a security issue that could allow hackers to access sensitive information from a website’s database. This vulnerability is caused by a lack of proper precautions when handling user input. As a result, attackers could add their own code to existing queries and potentially steal sensitive data.