Reflected Cross-Site Scripting in KingComposer Plugin for WordPress
CVE-2019-9910
6.1MEDIUM
What is CVE-2019-9910?
The KingComposer plugin version 2.7.6 for WordPress is vulnerable to a reflected cross-site scripting (XSS) issue. This vulnerability allows attackers to inject malicious scripts via the wp-admin/admin.php?page=kc-mapper request, leading to potential exploitation. Users of this plugin are at risk if they interact with crafted URLs that could execute unwanted scripts in their browsers.