Description
WordPress Plugin Gutenberg & Elementor Templates Importer For Responsive is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently execute various AJAX actions that could reset site data, inject malicious JavaScript in pages, modify theme customizer data, import .xml and .json files, or activate plugins. WordPress Plugin Gutenberg & Elementor Templates Importer For Responsive version 2.2.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.6 or latest
References
Related Vulnerabilities
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2016-5734)
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2009-0754)
Drupal Core 9.4.x Security Bypass (9.4.0 - 9.4.2)
WordPress Plugin WPCOM Member Malicious Code (1.3.16)
WordPress Plugin Crayon Syntax Highlighter Security Bypass (2.6.10)