The WP Private Content Plus plugin for WordPress is vulnerable to a security flaw called Cross-Site Request Forgery in versions up until 3.1. This vulnerability is caused by either a missing or incorrect nonce validation on the save_groups() function. This could allow unauthenticated attackers to add new group members if they are able to trick a site administrator into clicking on a link.