Page Builder KingComposer <= 2.9.6 - Open Redirect
18Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendepss 4.3%
probabilidad de explotación
4.3%top 10% de las CVE
explotación observada
noninguna fuente lo reporta
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users