The WP Security Question plugin for WordPress is vulnerable to unauthenticated attackers modifying its settings. This vulnerability affects versions up to 1.0.5 because the plugin does not have sufficient validation in place to protect against malicious activity. A malicious actor could use a forged request to trick an administrator into clicking on a link or performing some other action, allowing them to alter the plugin’s settings.