Description
WordPress Plugin Gutenberg & Elementor Templates Importer For Responsive is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently execute various AJAX actions that could reset site data, inject malicious JavaScript in pages, modify theme customizer data, import .xml and .json files, or activate plugins. WordPress Plugin Gutenberg & Elementor Templates Importer For Responsive version 2.2.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.6 or latest
References
Related Vulnerabilities
WordPress Plugin VDZ CallBack Cross-Site Scripting (1.14.5)
Atlassian Jira CVE-2021-39122 Vulnerability (CVE-2021-39122)
WordPress Plugin Adblock Blocker Arbitrary File Upload (0.0.1)
WordPress Plugin CMS Tree Page View Cross-Site Request Forgery (1.2.4)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-20151)