WordPress, a popular website building platform, has a security flaw that allows attackers to inject harmful code into web pages. This can happen when someone with certain access levels tries to use a feature called Template Part Block. The vulnerability affects versions up to 6.5.5 and can only be exploited by authenticated attackers with contributor-level access or higher.