#VU29191 Path traversal in Page Builder: KingComposer - Free Drag and Drop page builder by King-Theme
Published: June 22, 2020
Page Builder: KingComposer - Free Drag and Drop page builder by King-Theme
King-Theme
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences on the "bulk-delete" action. A remote authenticated attacker can recursively delete any folders and files by assigning the folder(s) relative path to the checked[] POST array.