The Process Steps Template Designer plugin for WordPress is vulnerable to malicious attacks through Cross-Site Request Forgery. This vulnerability affects versions up to 1.2.1 of the plugin. It is caused by incorrect or missing nonce validation on the save() function. This makes it possible for unauthenticated attackers to save field icons. They can do this by tricking a site administrator into clicking a link.