The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.9.3. This is due to a security nonce being leaked in the '/wp-admin/index.php' page. This makes it possible for authenticated attackers to change arbitrary WordPress options, delete arbitrary files/folders, and inject arbitrary content.
We have discovered 1,703 live websites that are affected by CVE-2020-36700.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,703 live websites (18% of King Composer install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 16 versions ( 76% of all versions) |
| 350 websites | |
| 136 websites | |
| 111 websites | |
| 95 websites | |
| 94 websites | |
| 61 websites | |
| 58 websites | |
| 54 websites | |
| 47 websites | |
| 45 websites |
| .com | 656 websites |
| .it | 87 websites |
| .de | 63 websites |
| .co.uk | 57 websites |
| .org | 50 websites |
| .ru | 49 websites |
| .pl | 48 websites |
| .com.br | 46 websites |
| .com.au | 44 websites |
| .net | 43 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | *,*** | ||
| ****.******.com | ***,*** | ||
| ******.net | ***,*** | ||
| ***********.com | ***,*** | ||
| *********.***.au | ***,*** | ||
| **********************.org | ***,*** | ||
| ****.jp | ***,*** | ||
| ***********.org | ***,*** | ||
| ******.com | ***,*** | ||
| ****.eu | ***,*** |
FAQ