The Locations plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This vulnerability affects version 3.2.1 and earlier. The attack is possible because the saveCustomFields() function does not have the correct security measures in place to prevent it. This means if an attacker can get a site administrator to click on a malicious link, they can update the custom field meta data without being logged in.