The Software Issue Manager plugin for WordPress is not secure and can be easily hacked through a vulnerability called Stored Cross-Site Scripting. This is because it doesn’t properly clean up and protect the information being entered and shown on the website. As a result, attackers who have Contributor-level access or higher can add harmful code to pages that will run whenever someone visits that page.