The URL Shortify WordPress plugin before version 1.5.1 has a security flaw that could allow someone with malicious intent to make an logged-in administrator delete a link or group without their knowledge. This is done by exploiting a lack of protection against a type of attack called Cross-Site Request Forgery.