The WP Prayer plugin, which is used on WordPress websites, has a security issue that allows attackers to delete prayers without proper authentication. This happens because the plugin does not have the necessary checks in place to verify the legitimacy of a request on the wpe_manage_prayer page. This means that someone who is not logged in can trick a site administrator into clicking a link that will delete prayers without their knowledge.