Vulnerabilities > CVE-2022-0165 - Unspecified vulnerability in King-Theme Kingcomposer 2.7.6/2.9.4
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |