Report
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them
Score:4.3
Severity:Medium
Version: 2.9.6
The plugin vendor has not patched this vulnerability at the moment.