Security Advisory

CVE-2021-39341

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-11-01 21:01:23
Last updated 2025-03-31 17:45:22
Assigner Wordfence
CVSS score 8.2
State PUBLISHED

Description

The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.