The USPS Shipping for WooCommerce plugin used on WordPress websites has a security issue called Cross-Site Request Forgery. This means that anyone who is not logged in can trick a site administrator into taking an unknown action, like clicking on a link. This vulnerability affects all versions up to 1.9.2 and the impact is currently unknown.