I'll admit I have zero insight and haven't looked into this, but at first glance, I don't understand why a desktop environment theme engine is unable to provide enough functionality for theme creators to do their thing without resorting to arbitrary command execution...
I trust KDE devs to address this quickly, but this is a pretty major oversight IMO...
Me: fixes exposure to vuln
Also me: grabs popcorn
This is going to be an interesting story once this all quiets down...