The Menu Swapper plugin for WordPress is not secure in versions up to 1.1.0.2. This means that a malicious user can potentially deceive a site administrator and cause them to take an action, such as clicking on a link, without them knowing. This is possible because the plugin does not have the necessary security measures in place to protect from Cross-Site Request Forgery.