QID 730589

Date Published: 2022-08-11

QID 730589: WordPress KingComposer Plugin Open Redirect Vulnerability

The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users.

Affected Versions:
Page Builder KingComposer prior to 2.9.6

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable plugin installation by sending a crafted payload to the webserver

Successful exploitation of the vulnerability may allow unauthenticated attackers to redirect users to malicious sites.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    There is no patch available at the moment. For more information, please refer to CVE-2022-0165

    CVEs related to QID 730589

    Software Advisories
    Advisory ID Software Component Link