A popular plugin for WordPress called TablePress has a security vulnerability that allows attackers to make web requests to any location on the internet. This can potentially give them access to internal information and services. To prevent this, the plugin developer has restricted the feature to only be used by administrators. However, it would be best if WordPress itself fixed this issue in their code.