Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).
Solution:
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.