A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim's browser.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-7296 A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim's browser.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T13:15:19.029Z

Reserved: 2020-06-25T00:00:00

Link: CVE-2020-15299

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-09T19:15:11.523

Modified: 2024-11-21T05:05:16.273

Link: CVE-2020-15299

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses