The WP Prayer plugin, used on WordPress websites, has a security issue called Cross-Site Request Forgery. This means that in versions 2.0.9 and below, the plugin does not properly check for a security code when changing email settings on the wpe_manage_email_settings page. This allows hackers to change the email settings without needing a password, as long as they can trick the website administrator into clicking a link.