.. / CVE-2022-0165

Exploit for WordPress Page Builder KingComposer <=2.9.6 - Open Redirect (CVE-2022-0165)

Description:

WordPress Page Builder KingComposer 2.9.6 and prior does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action (which is available to both unauthenticated and authenticated users).

Nuclei Template

View the template here CVE-2022-0165.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-0165.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2022-0165
https://wpscan.com/vulnerability/906d0c31-370e-46b4-af1f-e52fbddd00cb
https://github.com/ARPSyndicate/kenzer-templates
https://github.com/K3ysTr0K3R/CVE-2022-0165-EXPLOIT