CVE Published: 04/04/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: WPScan |
Vendor: Unknown |
Product: Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme Status : PUBLISHED
CVE-2021-25048 Description
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them