Bogus CVE. Spam.
From the PoC:
Replace the original DLL (such as Notepad++\plugins\NppExport\NppExport.dll) with a DLL file with the same name containing malicious code
If you replace parts of a program with malware then you can get malware to run. This is true of all software.