VulnerabilityModified
CVE-2022-0165
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users
MEDIUM 6.1EPSS 4.28%
Does this matter?
Lower severity and a low EPSS score (4.28%). Track it; it rarely justifies an emergency change on its own.
Description
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 4.28% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- king-theme/kingcomposer
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/906d0c31-370e-46b4-af1f-e52fbddd00cbExploit, Third Party Advisory
- https://wpscan.com/vulnerability/906d0c31-370e-46b4-af1f-e52fbddd00cbExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.