I know *very well* what’s a nonce, and I’ve been using nonces in WP since they were added in 2006, thank you.
Needed a plugin similar to yours 10 months ago, so I tried yours and noticed that either anybody could POST to the admin form, or could make a user with sufficient privileges POST to that form without having the intention of doing so (CSRF). Can’t remember but this was enough for me to ditch the plugin.
Using nonces fixes both situations.
Are you using nonces now?
Has this issue been fixed in the meantime?
I don’t know and I honestly don’t care. I don’t have time to download, install and review your plugin again. If you have, good for you and your users. If you haven’t, too bad.
You’re 10 months late as far as I’m concerned.
I’m not a user of your plugin (because of said vulnerability 10 months ago) so I’m not going to spend some of my free time to check if this issue is still to be fixed and make a PR if this is still required, sorry.
Bye.