The WPPizza plugin for WordPress has a security issue that could allow unauthorized changes to be made to its data. This is because it does not have a check in place for a certain capability on the admin_ajax function, which is used in multiple files. This vulnerability exists in versions 3.18.10 and below. As a result, those with subscriber-level access or higher could potentially change various plugin settings without proper authorization.