The WP Project Manager plugin for WordPress has a security vulnerability that allows hackers to insert harmful code into web pages. This can happen on versions up to 2.6.17 and can only affect certain types of WordPress installations. The vulnerability is caused by not properly filtering and escaping user input, and it can only be exploited by users with high levels of access.