Description
WordPress Plugin Starter Templates-Elementor, WordPress & Beaver Builder Templates is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently overwrite any page on the site with malicious JavaScript. WordPress Plugin Starter Templates-Elementor, WordPress & Beaver Builder Templates version 2.7.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7.1 or latest
References
Related Vulnerabilities
Jenkins Improper Input Validation Vulnerability (CVE-2017-1000391)
WordPress Plugin Rimons Twitter Widget Cross-Site Scripting (1.2.4)
WordPress Plugin WP Plugin Manager (WPPM) Cross-Site Scripting (1.6.4.b)
Nginx CVE-2013-2070 Vulnerability (CVE-2013-2070)
IBM RTC Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2020-4547)