PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2021-39341

8.2
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
optinmonster
Updated Sep 26, 2026View on NVD →
S4E scanner
highMisconfiguration~10 seconds

CVE-2021-39341 Scanner

CVE-2021-39341 Scanner - Information Disclosure vulnerability in OptinMonster Plugin

Used 2.8k times · 5.9k assets checked · domain, subdomain, ipv4

CVE history: optinmonster

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →