A Flickr plugin contains a reflected XSS vulnerability which would allow an unauthenticated attacker to do almost anything an admin user can do.
For this to happen, the administrator would have to be tricked into clicking on a link controlled by the attacker. It is easy to make these links very convincing.
view the full story here