includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.Referenceshttps://blog.nintechnet.com/unauthenticated-stored-xss-vulnerability-in-wordpress-onetone-theme-unpatched/