The WP-Backgrounds Lite plugin for WordPress has a security issue in versions up to 2.3. This vulnerability is called Cross-Site Request Forgery, and happens because the plugin does not have the proper security measures in place to prevent it. This means that if an attacker can get a site administrator to click a malicious link, they can save meta data in the website without the administrator’s permission.