The Base64 Encoder/Decoder WordPress plugin up to and including 0.9.2 does not have CSRF check in place when resetting its settings, which could allow malicious users to make a logged in admin reset them via a CSRF attack