I don't think RemoveExtraSpaces has any RCE, but it is overwriteable. The "hack" is tricking the user into overwriting it with a different function called RunScript.
It's like saying that any program running on my computer could exploit a remote code execution bug... I mean, yes, it could. But why would it, when it already has local execution rights?
The installation of an add-on shouldn’t inherently give it free reign, with the only possible defense being trust & source-code review.
It's just a game, so they don't take it very seriously, I guess. They could just revert transaction using their moderator powers if something bad happens.