The Lightweight Sidebar Manager plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery in versions up to and including 1.1.4. This is because it does not properly validate something called a ‘nonce’ when the metabox_save() function is used. This means that unauthenticated attackers could potentially trick a website administrator into performing an action, like clicking on a link, and thereby save data on the website.