A plugin called Paid Memberships Pro, used for restricting content, registering users, and managing paid subscriptions on WordPress websites, has a security issue. This issue, known as Cross-Site Request Forgery, affects all versions up to 2.12.10. The problem is caused by a missing or incorrect validation code, allowing attackers to perform unauthorized actions if they can trick a site administrator into clicking on a link. The extent of the potential harm from this vulnerability is not known.