WARNING: Global themes and widgets created by 3rd party developers for Plasma can and will run arbitrary code. You are encouraged to exercise extreme caution when using these products

That’s enough for you (and me), but times are changing. The developers are aware and they will take action as they think are apropriate. Here is the an excellent blog post by a KDE developer explaining the situation:

Lets not do too much speculating, I think we will receive further information soon enough.