The WP Prayer plugin for WordPress is vulnerable to a security issue called Cross-Site Request Forgery. This means that anyone who can trick a website administrator into clicking on a link can potentially harm the website. Versions of the plugin up to and including 1.6.5 have this security risk because the plugin is missing or incorrectly using a security feature called a “nonce” when saving and exporting plugin settings.