Input validation vulnerability in Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme 2.8.2

The Page Builder: KingComposer plugin for WordPress is vulnerable to a type of attack called “Stored Cross-Site Scripting”. This type of attack can allow malicious actors who have access to the post editor to insert malicious web scripts into pages that will be executed when someone visits the page. This vulnerability exists in versions of the plugin up to and including 2.8.1, due to a lack of proper input sanitization and output escaping.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.