The plugin called Custom CSS, JS & PHP for the website builder WordPress has a security issue where hackers can inject harmful code into web pages if they can trick a user into clicking on a link. This can happen because the plugin does not properly protect the URL, making it vulnerable to a type of attack called Reflected Cross-Site Scripting. This can affect all versions of the plugin up to and including version 2.3.0.