hi @sirrahikkala @steveokk
We’ve published version 2.3.3 which should address the CVE. We removed the nopriv WP actions as well as added a permission check so that users with access to the dashboard should be the only ones who can execute the privileged functions