WordPress Newspaper theme before 12 is susceptible to cross-site scripting. The does not sanitize a parameter before outputting it back in an HTML attribute via an AJAX action. An attacker can potentially execute malware, obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials.
View the template here CVE-2022-2627.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2022-2627