The Amministrazione Trasparente plugin for WordPress is vulnerable to a type of attack known as Cross-Site Request Forgery in versions up to 7.1. This is because the at_save_aturl_meta() function does not properly validate nonces, which are special codes used to verify requests. This means that malicious attackers can modify meta data if they can trick a site administrator into clicking a link.