PT-2022-7044 · WordPress · Page Builder Kingcomposer
Krzysztof Zając
·
Published
2022-02-16
·
Updated
2023-03-27
·
CVE-2022-0165
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Page Builder KingComposer WordPress plugin versions 2.9.6 and earlier
Description
The issue is related to the use of open redirection when handling the
kc get thumbn parameter in the admin-ajax.php script of the Page Builder KingComposer WordPress plugin. This can allow a remote attacker to redirect a user to an arbitrary URL. The kc get thumbn AJAX action is available to both unauthenticated and authenticated users, and it does not validate the id parameter before redirecting the user to it.Recommendations
For Page Builder KingComposer WordPress plugin versions 2.9.6 and earlier, consider disabling the
kc get thumbn AJAX action until a patch is available to prevent exploitation. Restrict access to the admin-ajax.php script to minimize the risk of redirection attacks. Avoid using the id parameter in the affected AJAX endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Page Builder Kingcomposer