The NotificationX plugin for WordPress has a security vulnerability that allows attackers to inject harmful code into the plugin’s content settings. This can only be done by someone with administrator-level permissions or higher and only affects certain types of installations.