S4E just found a medium [ai] private ip disclosure detection scanner
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0165 Scanner

Detects 'Open Redirect' vulnerability in Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme plugin for WordPress affects v. through 2.9.6.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0165
6.1
CVSS

The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme
2.9.6
Updated Aug 22, 2026View on NVD →
Detail

The Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme is a popular WordPress plugin that allows users to easily create and customize web pages using a drag and drop interface. This plugin is highly valued by web developers and designers as it simplifies the process of creating and editing web pages, making it easier to create professional and responsive websites. With over 100,000 active installations, the plugin is widely used by WordPress users globally.

However, security researchers have recently uncovered a vulnerability in the plugin known as CVE-2022-0165. This vulnerability allows a potential attacker to access sensitive user information by exploiting the id parameter in the kc_get_thumbn AJAX action. The plugin does not validate the id parameter before redirecting users to it, which makes it vulnerable to cyberattacks.

If exploited, this vulnerability can lead to significant data breaches. An attacker can use the information gained from the exploit to gain unauthorized access to user accounts and even sensitive business data. This can result in the compromise of entire systems, leading to financial losses, reputational damage, and legal liabilities.

At s4e.io, we offer pro features that provide powerful and efficient tools for identifying and managing security vulnerabilities in your digital assets. Our platform offers a reliable and easy-to-use tool for tracking and fixing vulnerabilities within your WordPress sites, ensuring that your digital assets are protected from cyberattacks. By leveraging our expertise and experience, you can rest assured that your web pages are free from vulnerabilities and remain safeguarded against attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, several precautions can be taken, including updating the plugin to the latest version or disabling the AJAX action altogether. Other measures include:

  • Installing security plugins to monitor and protect against vulnerabilities in WordPress.
  • Regularly backing up website data to an offline location.
  • Keeping the WordPress core, themes, and plugins updated to the latest version available.
  • Using strong passwords for user accounts and limiting user access to sensitive data.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0165 scanner - Open Redirect vulnerability in Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme plugin for WordPress S4E