A reflected cross-site scripting (XSS) vulnerability impacting 100,000 websites has been patched in the KingComposer WordPress plugin. A patched version of the plugin, version 2.9.5, was released on June 29. While approximately 62% of users have updated to version 2.9.5, around 38% of websites with KingComposer enabled are still at risk of exploit.
The opinions expressed in this post belongs to the individual contributors and do not necessarily reflect the views of Information Security Buzz.