A popular tool used to create visually appealing content on WordPress websites has a security vulnerability that could potentially be exploited by hackers. This vulnerability, known as Cross-Site Request Forgery, affects all versions of the plugin up to 2.1.20. Essentially, the plugin does not properly check for a security code before carrying out certain actions, making it possible for someone without proper authorization to manipulate the website. This can be done by tricking the website administrator into clicking on a malicious link.