CVE-2021-25048
04.04.2022, 16:15
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them
| Vendor | Product | Version |
|---|---|---|
| king-theme | kingcomposer | 𝑥 ≤ 2.9.6 |
𝑥
= Vulnerable software versions