A popular plugin for WordPress called “Ultimate Blocks” has a security issue where attackers can inject harmful code into website pages. This is because the plugin does not properly clean up user input and output. This means that unauthorized people with certain levels of access can add dangerous scripts to pages, which will run whenever someone visits them.