The Cool Timeline plugin for WordPress has a security vulnerability in versions up to 2.0.2. This vulnerability allows unauthenticated attackers to save field icons without authorization. This is possible because the plugin is missing or incorrectly validating the ctl_save() function. To exploit this vulnerability, an attacker would need to fool a site administrator into clicking on a malicious link.