CVE-2022-0165 describes an open redirect vulnerability in the KingComposer WordPress plugin up to version 2.9.6, affecting both unauthenticated and authenticated users. This medium-severity vulnerability (CVSS 6.1) allows attackers to redirect users to arbitrary malicious sites due to improper validation of the 'id' parameter in the kc_get_thumbn AJAX action. While there is no evidence of active exploitation or KEV listing, a Nuclei template exists for detection, and the FAUCET Risk Score is high at 98/100, indicating a significant potential risk despite low community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.9.6CPE matchmatch criteria | cpe:2.3:a:king-theme:kingcomposer:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.