CVE-2021-25048
EUVD-2021-1196004.04.2022, 16:15
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| king-theme | kingcomposer | 𝑥 ≤ 2.9.6 |
𝑥
= Vulnerable software versions