Extension WordPress

Vulnérabilités Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme

Cette page rassemble les failles publiées pour Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
6Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme

8 fiches

CVE-2021-25048 Élevée · 8,5
Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme

Page Builder KingComposer <= 2.9.6 – Authenticated Arbitrary Profile Creation and Stored Cross-Site Scripting

The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them

Versions affectées

*-2.9.6

Correctif

Non indiqué

Publication

14/03/2022

CVE-2020-36709 Moyenne · 5,5
Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme

Page Builder: KingComposer < 2.9.4 – Stored Cross-Site Scripting

The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in versions before 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary…

Versions affectées

[*, 2.9.4)

Correctif

2.9.4

Publication

09/07/2020

CVE-2020-15299 Moyenne · 6,1
Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme <= 2.9.4 – Reflected Cross-Site Scripting

A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed…

Versions affectées

*-2.9.4

Correctif

2.9.5

Publication

25/06/2020

CVE-2020-36701 Élevée · 8,8
Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme

Page Builder: KingComposer < 2.9.4 – Arbitrary File Upload

The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_bulk_action' function in the 'kingcomposer/includes/kc.extensions.php' file. This makes it possible for authenticated users with author level…

Versions affectées

*-2.9.3

Correctif

2.9.4

Publication

15/06/2020

CVE-2020-36700 Élevée · 8,8
Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme

Page Builder: KingComposer < 2.9.4 – Authorization Bypass due to Improper Access Control

The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.9.3. This is due to a security nonce being leaked in the '/wp-admin/index.php' page. This makes it possible for authenticated…

Versions affectées

*-2.9.3

Correctif

2.9.4

Publication

15/06/2020

Vulnérabilité Moyenne · 6,4
Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme

Page Builder: KingComposer < 2.8.2 – Authenticated Stored Cross-Site Scripting

The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

[*, 2.8.2)

Correctif

2.8.2

Publication

23/04/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités