A popular plugin for WordPress called “Paid Memberships Pro” has a security vulnerability in versions up to 2.12.10. This means that unauthorized people could trick users into subscribing, changing, or canceling their membership by sending them a fake request. To fix this issue, the plugin needs to validate a special code called a “nonce.”