A plugin called “Redirection for Contact Form 7” in WordPress has a security flaw that allows anyone to delete files on the server without authorization. This could lead to hackers being able to run their own code on the website if they delete the right file.