The WP e-Commerce plugin for WordPress is vulnerable to a security issue known as Cross-Site Request Forgery (CSRF). This vulnerability is present in versions up to and including 1.2. It occurs because the order_delivery_date_settings() function does not properly validate nonce values. This means an unauthenticated attacker could send a malicious link to a site administrator and potentially modify the plugin’s settings if the administrator clicks on the link.