CVE-2021-25048

CVE-2021-25048: KingComposer <= 2.9.6 - Subscriber+ Stored Cross-Site Scripting

Vendor Unknown
Product Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme
Weakness CWE-79 · XSS
Published April 4, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them

Key dates

02Disclosure timeline

April 4, 2022 CVE published
August 3, 2024 Record updated

Related vulnerabilities

04Related CVE