The BuddyBuilder plugin for WordPress is not secure in versions up to 1.7.4. If someone tricks a site administrator into clicking a link, they can make unauthorized changes to the plugin settings. This is because the plugin does not have the proper security measures in place to prevent this from happening.