← Back to browse · API

CVE-2021-39341

Severity
HIGH
CVSS
8.2
EPSS
0.21929
Risk score
40.48
CISA KEV
No
PoC
No
Published
2021-11-01
Modified
2025-03-31
First seen
2026-08-07
Aliases
EUVD-2021-25702, GHSA-WHCC-JGF3-Q7PM
Products
OptinMonster Popup Builder Team:OptinMonster 2.6.4 ≤2.6.4
Sources
euvd EUVD-2021-25702

Description

The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.

References