Patched stored XSS vulnerabilities in the REST API request handling and Lightbox component, and fixed a missing authorization check in AI image uploads. Users without the unfiltered_html capability could previously inject malicious scripts via Elementor post data or crafted lightbox content. All three issues are resolved by enforcing proper input...