The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2021-11-01T21:01:23.439693Z
Updated: 2024-09-17T02:47:51.399Z
Reserved: 2021-08-20T00:00:00
Link: CVE-2021-39341
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-11-01T21:15:07.863
Modified: 2024-11-21T06:19:16.893
Link: CVE-2021-39341
Redhat
No data.