Introduction: The Automatic Door Opener
UPnP (Universal Plug and Play) was designed to make networking easy. It allows a device (like a gaming console or a printer) to tell your router: "Hey, I need to talk to the internet, please open Port 3000 for me." The router says "Sure!" and creates a hole in your firewall automatically.
The Security Nightmare
The problem is that if a piece of 'Malware' or a 'Rogue Device' gets onto your computer, it can use UPnP to open a hole for a hacker without you ever knowing. The hacker now has a direct 'IP-to-IP' path into your private network.
Conclusion
UPnP is a massive security risk in the modern era. While convenient, the risks usually outweigh the benefits for the average home user. Test for UPnP holes here.