A popular WordPress plugin called “Export All Posts, Products, Orders, Refunds & Users” has a security vulnerability. This means that someone who is not logged in can inject a harmful code into the plugin. However, this only affects websites that have another plugin or theme installed that also has a security vulnerability. If this is the case, the attacker may be able to delete files, access private information, or run their own code.