The Categorify plugin for WordPress has a security issue that allows attackers to make unauthorized changes to categories. This vulnerability affects all versions of the plugin, up to and including version 1.0.7.4. The problem is caused by a lack of proper validation when using the categorifyAjaxRenameCategory function. This means that if someone can trick a site administrator into clicking a link, they can manipulate the categories without authorization.