The WordPress plugin DW Question & Answer is vulnerable to a Cross-Site Request Forgery in versions up to and including 1.5.8. This means that attackers who can trick a site administrator into clicking a link can update answers to questions without being signed in. This vulnerability is a result of missing or incorrect validation on the update_answer() function.