The Market Exporter plugin for WordPress has a security flaw that allows unauthorized changes to be made to its data. This is because the update_settings() function in versions up to 2.0.21 does not properly check for permissions. This means that individuals with subscriber-level access or higher can make changes to the plugin’s settings without proper authorization.