Input validation vulnerability in Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme 2.9.3

The Page Builder: KingComposer plugin for WordPress is vulnerable to a security issue in which unauthorized users can upload files to the server. This vulnerability affects versions up to 2.9.3, and is caused by a function called ‘process_bulk_action’ found in the ‘kingcomposer/includes/kc.extensions.php’ file. This security issue allows users with author level permissions and higher to upload any type of file to the server, which can be used to run code on the server.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.