The Multiple Page Generator Plugin for WordPress, also known as the MPG plugin, has a security issue in versions up to 3.4.0. This vulnerability, called Cross-Site Request Forgery, occurs because the plugin does not properly check the authenticity of requests when deleting a project. This means that someone who is not logged in can trick a site administrator into unknowingly deleting a project by getting them to click on a link.