Description
WordPress Plugin Gutenberg & Elementor Templates Importer For Responsive is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently execute various AJAX actions that could reset site data, inject malicious JavaScript in pages, modify theme customizer data, import .xml and .json files, or activate plugins. WordPress Plugin Gutenberg & Elementor Templates Importer For Responsive version 2.2.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.6 or latest
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Gift Cards Security Bypass (1.3.7)
WordPress Plugin is_human() 'type' Parameter Remote Command Injection (1.4.2)
WordPress Plugin WP Dev Powers:ACF Color Coded Field Types Security Bypass (1.0)
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2015-8103)
WordPress Plugin WP Database Backup Unspecified Vulnerability (4.1)