Extension WordPress
Vulnérabilités Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme
Cette page rassemble les failles publiées pour Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme
8 fiches
Page Builder KingComposer <= 2.9.6 – Authenticated Arbitrary Profile Creation and Stored Cross-Site Scripting
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them
*-2.9.6
Non indiqué
14/03/2022
Page Builder KingComposer <= 2.9.6 – Open Redirect
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users
*-2.9.6
Non indiqué
16/02/2022
Page Builder: KingComposer < 2.9.4 – Stored Cross-Site Scripting
The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in versions before 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary…
[*, 2.9.4)
2.9.4
09/07/2020
Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme <= 2.9.4 – Reflected Cross-Site Scripting
A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed…
*-2.9.4
2.9.5
25/06/2020
Page Builder: KingComposer < 2.9.4 – Arbitrary File Upload
The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_bulk_action' function in the 'kingcomposer/includes/kc.extensions.php' file. This makes it possible for authenticated users with author level…
*-2.9.3
2.9.4
15/06/2020
Page Builder: KingComposer < 2.9.4 – Authorization Bypass due to Improper Access Control
The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.9.3. This is due to a security nonce being leaked in the '/wp-admin/index.php' page. This makes it possible for authenticated…
*-2.9.3
2.9.4
15/06/2020
Page Builder: KingComposer < 2.8.2 – Authenticated Stored Cross-Site Scripting
The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
[*, 2.8.2)
2.8.2
23/04/2019
KingComposer <= 2.8 – Reflected Cross-Site Scripting
The kingcomposer plugin up to 2.8 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS.
*-2.8
2.8.1
05/02/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.