A popular plugin for WordPress called WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons, is not secure. This means that anyone, even without permission, can trick a website administrator into making changes by getting them to click on a link. This vulnerability affects all versions up to 1.6.9.