A plugin called CM Answers, which helps build online forums on WordPress, has a security issue called Cross-Site Request Forgery. This can happen in all versions up to 3.3.3 because the plugin does not properly check for a security code. This means that someone who is not logged in to the site could trick an administrator into clicking a link that gives them unauthorized access.