CVE-2021-25048
04.04.2022, 16:15
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them
Vendor | Product | Version |
---|---|---|
king-theme | kingcomposer | 𝑥 ≤ 2.9.6 |
𝑥
= Vulnerable software versions