A plugin for WordPress called “Paid Memberships Pro” has a security issue where attackers can trick site administrators into making changes to the settings without their knowledge. This can happen if the administrator clicks on a link sent by the attacker.