The ElasticPress plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This affects versions 3.5.3 and earlier. The issue is caused by the epio_send_autosuggest_allowed() function not having the right security measures. This means that an attacker who can trick a site administrator into clicking on a link could send allowed parameters for autosuggest to elasticpress[.]io without needing to be authenticated.