The Customizr theme for WordPress is not secure in versions up to 4.4.21 because it does not properly check for a security code called a “nonce.” This means that someone without permission can trick a website administrator into doing something, like clicking a link, and dismiss important notices.