Newspaper Theme versions 6.4 to 6.7.1 for WordPress lacked proper options access control through td_ajax_update_panel, which led to a Privilege Escalation vulnerability.
id: CVE-2016-10972
info:
name: Newspaper Theme 6.4–6.7.1 - Privilege Escalation
author: pussyca
...