plugin

Kingcomposer Vulnerabilities

26 known security issues reported for the Kingcomposer WordPress plugin. Most recent disclosed Jun 7, 2023.

4 high 4 medium

Running Kingcomposer on your site? Check whether your installed version is affected.

Scan your site free

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.4

unknown

[en] The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_bulk_action' function in the 'kingcomposer/includes/kc.extensions.php' file. This makes it possible for authenticated users with author level permissions and above to...

Affected:
up to 2.9.4
Fixed in:
2.9.4
Disclosed:
Jun 7, 2023

CVE-2020-36701 on NVD →

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.4

unknown

[en] The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.9.3. This is due to a security nonce being leaked in the '/wp-admin/index.php' page. This makes it possible for authenticated attackers to change arbitrary WordPress options, delete arbitra...

Affected:
up to 2.9.4
Fixed in:
2.9.4
Disclosed:
Jun 7, 2023

CVE-2020-36700 on NVD →

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.4

unknown

[en] The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in versions before 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whene...

Affected:
up to 2.9.4
Fixed in:
2.9.4
Disclosed:
Jun 7, 2023

CVE-2020-36709 on NVD →

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] <= 2.9.6 (unfixed + closed)

unknown

[en] The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them

Affected:
up to 2.9.6
Fix:
No patched version reported
Disclosed:
Apr 4, 2022

CVE-2021-25048 on NVD →

Page Builder KingComposer <= 2.9.6 - Authenticated Arbitrary Profile Creation and Stored Cross-Site Scripting

high

The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them

CVSS:
8.5
Affected:
up to 2.9.6
Fix:
No patched version reported
Disclosed:
Mar 14, 2022

CVE-2021-25048 on NVD →

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] <= 2.9.6 (unfixed + closed)

unknown

[en] The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users

Affected:
up to 2.9.6
Fix:
No patched version reported
Disclosed:
Mar 14, 2022

CVE-2022-0165 on NVD →

Page Builder KingComposer <= 2.9.6 - Open Redirect

high

The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users

CVSS:
8.8
Affected:
up to 2.9.6
Fix:
No patched version reported
Disclosed:
Feb 16, 2022

CVE-2022-0165 on NVD →

Page Builder: KingComposer < 2.9.4 - Stored Cross-Site Scripting

medium

The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in versions before 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...

CVSS:
5.5
Affected:
up to 2.9.4
Fixed in:
2.9.4
Disclosed:
Jul 9, 2020

CVE-2020-36709 on NVD →

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.5

unknown

[en] A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the vict...

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Jul 9, 2020

CVE-2020-15299 on NVD →

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.4

unknown

The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in versions before 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...

Affected:
up to 2.9.4
Fixed in:
2.9.4
Disclosed:
Jul 9, 2020

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme <= 2.9.4 - Reflected Cross-Site Scripting

medium

A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim's...

CVSS:
6.1
Affected:
up to 2.9.4
Fixed in:
2.9.5
Disclosed:
Jun 25, 2020

CVE-2020-15299 on NVD →

Page Builder: KingComposer < 2.9.4 - Authorization Bypass due to Improper Access Control

high

The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.9.3. This is due to a security nonce being leaked in the '/wp-admin/index.php' page. This makes it possible for authenticated attackers to change arbitrary WordPress options, delete arbitrary fi...

CVSS:
8.8
Affected:
up to 2.9.3
Fixed in:
2.9.4
Disclosed:
Jun 15, 2020

CVE-2020-36700 on NVD →

Page Builder: KingComposer < 2.9.4 - Arbitrary File Upload

high

The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_bulk_action' function in the 'kingcomposer/includes/kc.extensions.php' file. This makes it possible for authenticated users with author level permissions and above to uplo...

CVSS:
8.8
Affected:
up to 2.9.3
Fixed in:
2.9.4
Disclosed:
Jun 15, 2020

CVE-2020-36701 on NVD →

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.4 (unfixed + closed)

unknown

WordPress Options Change vulnerability discovered by NinTechNet in WordPress KingComposer plugin (versions <= 2.9.2).

Affected:
up to 2.9.4
Fix:
No patched version reported
Disclosed:
Jun 15, 2020

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.4 (unfixed + closed)

unknown

Arbitrary Files/Folders Deletion vulnerability discovered by NinTechNet in WordPress KingComposer plugin (versions <= 2.9.2).

Affected:
up to 2.9.4
Fix:
No patched version reported
Disclosed:
Jun 15, 2020

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.4 (unfixed + closed)

unknown

Content Injection vulnerability discovered by NinTechNet in WordPress KingComposer plugin (versions <= 2.9.2).

Affected:
up to 2.9.4
Fix:
No patched version reported
Disclosed:
Jun 15, 2020

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.4 (unfixed + closed)

unknown

Stored Cross-Site Scripting (XSS) vulnerability discovered by NinTechNet in WordPress KingComposer plugin (versions <= 2.9.2).

Affected:
up to 2.9.4
Fix:
No patched version reported
Disclosed:
Jun 15, 2020

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.4 (unfixed + closed)

unknown

Remote Code Execution (RCE) vulnerability discovered by NinTechNet in WordPress KingComposer plugin (versions <= 2.9.2).

Affected:
up to 2.9.4
Fix:
No patched version reported
Disclosed:
Jun 15, 2020

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.4

unknown

The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.9.3. This is due to a security nonce being leaked in the '/wp-admin/index.php' page. This makes it possible for authenticated attackers to change arbitrary WordPress options, delete arbitrary fi...

Affected:
up to 2.9.4
Fixed in:
2.9.4
Disclosed:
Jun 15, 2020

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.4

unknown

The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_bulk_action' function in the 'kingcomposer/includes/kc.extensions.php' file. This makes it possible for authenticated users with author level permissions and above to uplo...

Affected:
up to 2.9.4
Fixed in:
2.9.4
Disclosed:
Jun 15, 2020

Page Builder: KingComposer < 2.8.2 - Authenticated Stored Cross-Site Scripting

medium

The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers able to access the post editor to inject arbitr...

CVSS:
6.4
Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Apr 23, 2019

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.8.2

unknown

The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers able to access the post editor to inject arbitr...

Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Apr 23, 2019

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.8.1

unknown

[en] The kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS.

Affected:
up to 2.8.1
Fixed in:
2.8.1
Disclosed:
Mar 21, 2019

CVE-2019-9910 on NVD →

KingComposer <= 2.8 - Reflected Cross-Site Scripting

medium

The kingcomposer plugin up to 2.8 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS.

CVSS:
6.1
Affected:
up to 2.8
Fixed in:
2.8.1
Disclosed:
Feb 5, 2019

CVE-2019-9910 on NVD →

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.9.4

unknown

Jerome Bruandet, from nintechnet, discovered multiple issues such as authenticated WordPress options change, content injection, stored Cross-Site Scripting (XSS), arbitrary file deletion and remote code execution.

Affected:
up to 2.9.4
Fixed in:
2.9.4

Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme [kingcomposer] < 2.8.2

unknown

An user with the Contributor or Author privileges can inject arbitrary Javascript code in a KC section. When an admin or editor opens the malicious KC section the arbitrary JS code runs.

Affected:
up to 2.8.2
Fixed in:
2.8.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database