The YITH WooCommerce Popup plugin for WordPress has a security issue that puts it at risk for Cross-Site Request Forgery. This can happen in any version of the plugin, including the most recent one (1.48.0). The problem is that a certain function doesn’t properly check for a special code, making it possible for someone without authorization to trick the site’s administrator into doing something, like clicking on a link.