The plugin re-introduced a CSRF bypass issue in v4.1.22, as the nonce is only checked if present in the request.
CSRF
ErwanLR
Yes
2020-12-15 (about 2 years ago)
2020-12-16 (about 2 years ago)