A popular plugin for WordPress, called Paid Memberships Pro, has a security flaw in versions up to 3.0.5. This flaw allows attackers who have administrator-level access to the site to add their own code into the existing code, which can then be used to get private information from the site’s database.