CVE-2020-36701
Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme
Minimum safe version
2.9.5
Update to 2.9.5 or later to address 11 fixable vulnerabilities
CVE-2020-36700
CVE-2020-36709
KingComposer - Authenticated Stored XSS
KingComposer < 2.9.4 - Multiple Critical Issues
Page Builder: KingComposer < 2.8.2 - Authenticated Stored Cross-Site Scripting
Page Builder: KingComposer < 2.9.4 - Arbitrary File Upload
Page Builder: KingComposer < 2.9.4 - Authorization Bypass due to Improper Access Control
Page Builder: KingComposer < 2.9.4 - Stored Cross-Site Scripting
WordPress KingComposer plugin <= 2.9.2 - Remote Code Execution (RCE) vulnerability
WordPress KingComposer plugin <= 2.9.2 - Stored Cross-Site Scripting (XSS) vulnerability
WordPress KingComposer plugin <= 2.9.2 - Content Injection vulnerability
WordPress KingComposer plugin <= 2.9.2 - Arbitrary Files/Folders Deletion vulnerability
WordPress KingComposer plugin <= 2.9.2 - WordPress Options Change vulnerability
CVE-2021-25048
CVE-2019-9910
CVE-2020-15299
CVE-2022-0165