King Theme maintains a narrowly scoped line of WordPress page-builder plugins, centered on the KingComposer product and its variants, that serve as visual design tools for website construction. The vendor's vulnerability disclosures reflect the input-handling and privilege-management demands typical of WordPress plugins that operate within shared hosting environments. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by King Theme over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15299MEDIUM A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_onl | Jul 9, 2020 | 6.1 | 46 | NO | NO |
CVE-2022-0165MEDIUM The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to bot | Mar 14, 2022 | 6.1 | 32 | NO | YES |
CVE-2020-36701HIGH The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_bulk_action' function in the 'k | Jun 7, 2023 | 8.8 | 25 | NO | NO |
CVE-2020-36700HIGH The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.9.3. This is due to a security nonce being leaked in t | Jun 7, 2023 | 8.8 | 25 | NO | NO |
CVE-2021-25048MEDIUM The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitr | Apr 4, 2022 | 5.4 | 20 | NO | NO |
CVE-2020-36709MEDIUM The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in versions before 2.9.4 due to insufficient input sanitization a | Jun 7, 2023 | 4.8 | 17 | NO | NO |
CVE-2019-9910MEDIUM The kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS. | Mar 22, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by King Theme.
Media articles that mention a CVE ID that affects a product developed by King Theme — matched by CVE ID, not by vendor name.