The optinmonster plugin before 1.1.4.6 for WordPress has incorrect access control for shortcodes because of a nonce leak.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://wordpress.org/plugins/optinmonster/#developers | release notes product |
http://www.pritect.net/blog/optinmonster-1-1-4-6-security-vulnerability | third party advisory |