This issue has been responsibly disclosed to the vendor and submitted to the WPScan vulnerability database. Full technical details and proof of concept will be published here after a CVE has been assigned and a fix has been released. Status: Reported - awaiting CVE assignment and vendor patch.