CVE-2022-0165

CVE-2022-0165: Page Builder KingComposer <= 2.9.6 - Open Redirect

Vendor Unknown
Product Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme
Weakness CWE-601 · Open redirect
Published March 14, 2022
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users

Key dates

02Disclosure timeline

March 14, 2022 CVE published
August 2, 2024 Record updated