The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used for sending spam emails.
- https://wpscan.com/vulnerability/46b634f6-92bc-4e00-a4c0-c25135c61922
- https://github.com/20142995/nuclei-templates
- https://github.com/ARPSyndicate/cvemon