Description The plugin does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins perform such actions via a CSRF attack
Make an admin open an HTML file containing:
The Twitter connection will be removed (API tokens reset to ''
)