WordPress Newspaper theme before 12 is susceptible to cross-site scripting. The does not sanitize a parameter before outputting it back in an HTML attribute via an AJAX action. An attacker can potentially execute malware, obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials.
id: CVE-2022-2627
info:
name: WordPress Newspaper < 12 - Cross-Site Scripting
author: ramondunk
...