Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme

Vulnerabilities 18Slug kingcomposerLatest version 2.6Plugin page →

Minimum safe version

2.9.5

Update to 2.9.5 or later to address 11 fixable vulnerabilities

Latest available2.6 ⚠ 7 vulnerabilities have no fix
High 8.8
2023-06-07< 2.9.4

CVE-2020-36701

High 8.8
2023-06-07< 2.9.4

CVE-2020-36700

Medium 5.5
2023-06-07< 2.9.4

CVE-2020-36709

N/A
< 2.8.2

KingComposer - Authenticated Stored XSS

N/A
< 2.9.4

KingComposer &lt; 2.9.4 - Multiple Critical Issues

N/A
2019-04-23< 2.8.2

Page Builder: KingComposer < 2.8.2 - Authenticated Stored Cross-Site Scripting

N/A
2020-06-15< 2.9.4

Page Builder: KingComposer < 2.9.4 - Arbitrary File Upload

N/A
2020-06-15< 2.9.4

Page Builder: KingComposer < 2.9.4 - Authorization Bypass due to Improper Access Control

N/A
2020-07-09< 2.9.4

Page Builder: KingComposer < 2.9.4 - Stored Cross-Site Scripting

N/A Unfixed Closed
2020-06-15< 2.9.4

WordPress KingComposer plugin <= 2.9.2 - Remote Code Execution (RCE) vulnerability

N/A Unfixed Closed
2020-06-15< 2.9.4

WordPress KingComposer plugin <= 2.9.2 - Stored Cross-Site Scripting (XSS) vulnerability

N/A Unfixed Closed
2020-06-15< 2.9.4

WordPress KingComposer plugin <= 2.9.2 - Content Injection vulnerability

N/A Unfixed Closed
2020-06-15< 2.9.4

WordPress KingComposer plugin <= 2.9.2 - Arbitrary Files/Folders Deletion vulnerability

N/A Unfixed Closed
2020-06-15< 2.9.4

WordPress KingComposer plugin <= 2.9.2 - WordPress Options Change vulnerability