A Missing Authorization vulnerability in the Ashe theme for WordPress, affecting versions up to and including 2.266, has been identified. This issue allows attackers to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions. The vulnerability has a CVSS score of 4.3 and a severity rating of MEDIUM. It can be exploited over the network with low privileges [truncated]
The Royal Addons for Elementor plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the 'button_text' parameter in all versions up to, and including, 1.7.1049. This is due to insufficient input sanitization and output escaping. Authenticated attackers with contributor level access and above can inject arbitrary web scripts in pages that will execute when a user accesses an injected pag [truncated]