The CM Answers WordPress Forum Plugin is at risk of being accessed without permission. This is because there is a missing security check in the plugin’s function, in all versions up to 3.2.6. This could allow attackers who are logged in with Subscriber-level access or higher to do things they are not supposed to do.