Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2024-11-21

CVE-2021-25048 - Kingcomposer Plugin

The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them

PLUGIN Kingcomposer

CVE-2021-25048

MEDIUM CVSS 5.4 2022-04-04
Threat Entry Updated 2024-11-21

CVE-2022-0165 - Kingcomposer Plugin

The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users

PLUGIN Kingcomposer

CVE-2022-0165

MEDIUM CVSS 6.1 2022-03-14
Scroll to top