The YaySMTP plugin used in WordPress has a security issue that allows hackers to access sensitive information from the database. This is because the plugin does not properly protect against SQL Injection attacks. This vulnerability affects versions up to 6.8.1, and can be exploited by attackers with administrator-level access or higher.