The Paid Memberships Pro plugin for WordPress, versions up to and including 2.4.2, is vulnerable to Cross-Site Request Forgery. This means that attackers who are not authenticated can save pages via a forged request if they can get a site administrator to take an action, such as clicking on a link. This is because the pmpro_page_save() function does not have valid nonce validation.