WordPress Page Builder KingComposer 2.9.6 and prior does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action (which is available to both unauthenticated and authenticated users).
View the template here CVE-2022-0165.yaml
References:
https://github.com/ARPSyndicate/cvemon