The WpEvently plugin for WordPress has a security issue that can allow hackers to inject malicious code into website pages. This vulnerability affects all versions up to 4.4.2, and is caused by a lack of proper protection for user input and output. This means that attackers with Contributor-level access or higher can insert harmful code that will run whenever a user visits the affected page.