Description
WordPress Page Builder KingComposer 2.9.6 and prior does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action (which is available to both unauthenticated and authenticated users).
WordPress Page Builder KingComposer 2.9.6 and prior does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action (which is available to both unauthenticated and authenticated users).
id: CVE-2022-0165
info:
name: WordPress Page Builder KingComposer <=2.9.6 - Open Redirect
author: akincibor
severity: medium
description: WordPress Page Builder KingComposer 2.9.6 and prior does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action (which is available to both unauthenticated and authenticated users).
impact: |
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the execution of further attacks.
remediation: |
Update to the latest version of KingComposer (>=2.9.7) to fix the open redirect vulnerability.
reference:
- https://wpscan.com/vulnerability/906d0c31-370e-46b4-af1f-e52fbddd00cb
- https://nvd.nist.gov/vuln/detail/CVE-2022-0165
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/K3ysTr0K3R/CVE-2022-0165-EXPLOIT
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cvss-score: 6.1
cve-id: CVE-2022-0165
cwe-id: CWE-601
epss-score: 0.0428
epss-percentile: 0.90601
cpe: cpe:2.3:a:king-theme:kingcomposer:*:*:*:*:*:wordpress:*:*
metadata:
max-request: 1
vendor: king-theme
product: kingcomposer
framework: wordpress
tags: cve,cve2022,wp-plugin,redirect,wordpress,wp,wpscan,king-theme,vuln
http:
- method: GET
path:
- "{{BaseURL}}/wp-admin/admin-ajax.php?action=kc_get_thumbn&id=https://interact.sh"
matchers:
- type: regex
part: header
regex:
- '(?m)^(?:Location\s*?:\s*?)(?:https?://|//)(?:[a-zA-Z0-9\-_\.@]*)interact\.sh.*$'
# digest: 490a0046304402201ec713bac1d4deeb2229e38f8655d366b5b8da15b63da9414b5859940abad43b022070f0e1772ef91bc105fb02d97749cee793987f22b0c84f942bb6888be90bee47:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.