Access violation vulnerability in Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation 2.6.4

The OptinMonster WordPress plugin has a security issue that affects versions up to and including 2.6.4. This issue can allow malicious web scripts to be injected on sites with the plugin installed and it can also lead to the disclosure of sensitive information and unauthorized changes to settings. The cause of the issue is an insufficient authorization validation process via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.