I wrote a blog post on the technique used by this plugin here a while back. Many WAF devices can be tricked into believing a request is from itself, and therefore trusted, if specific headers are present.
more here.........https://www.codewatch.org/blog/?p=408
more here.........https://www.codewatch.org/blog/?p=408