The Easy Testimonials plugin for WordPress is not secure in versions up to and including 3.6.1. This means that attackers who are not authenticated (not logged in) can alter the information stored by the plugin by sending a link to the site administrator. The link tricks the administrator into performing an action, such as clicking it, which changes the information stored by the plugin. This is due to the missing or incorrect validation of something called nonce on the saveCustomFields() function.