The Opal Estate plugin for WordPress has a vulnerability in versions up to 1.6.11 that could allow unauthenticated attackers to set and remove featured properties. This is because the plugin is not doing enough to validate certain requests, which can be forged. An attacker can exploit this if a website administrator unknowingly clicks on a malicious link.