The Legal Pages plugin for WordPress is not secure in versions up to 1.3.8. An unauthenticated attacker can potentially manipulate the plugin in order to delete posts and insert template data without the administrator’s permission, provided they are able to trick the administrator into clicking a link.