The Top 10 – Popular posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 3.2.3 and earlier. This means that unauthenticated attackers can clear the plugin’s cache by tricking a site administrator into clicking on a link or performing another action. This happens because the plugin has either incorrect or missing validation on the tptn_ajax_clearcache function.