Page Builder KingComposer <= 2.9.6 – Open Redirect
-
The plugin does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action, available to both unauthenticated and authenticated users.
https://wpscan.com/vulnerability/906d0c31-370e-46b4-af1f-e52fbddd00cb
Any ideas? Can someone patch this security bug?
Thanks in advance
Viewing 8 replies - 1 through 8 (of 8 total)
Viewing 8 replies - 1 through 8 (of 8 total)
- The topic ‘Page Builder KingComposer <= 2.9.6 – Open Redirect’ is closed to new replies.