Vulnerability record · CVE-2020-15299 · published 9 July 2020
CVE-2020-15299: KingComposer WordPress plugin reflected XSS via AJAX preset parameter
KKing Theme · Kingcomposer
KingComposer through 2.9.4 for WordPress contains a reflected cross-site scripting flaw. An attacker can craft an install_online_preset AJAX request carrying base64-encoded JavaScript in the kc-online-preset-data POST parameter, which executes in the victim's browser. It matters because the plugin was widely deployed and the flaw lets script run in the context of a logged-in victim's session.
Description
A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim's browser.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityPublic exploit references and a high EPSS percentile make exploitation likely, though the medium CVSS score and required user interaction temper the severity.
What it is
KingComposer through 2.9.4 for WordPress contains a reflected cross-site scripting flaw. An attacker can craft an install_online_preset AJAX request carrying base64-encoded JavaScript in the kc-online-preset-data POST parameter, which executes in the victim's browser. It matters because the plugin was widely deployed and the flaw lets script run in the context of a logged-in victim's session.
Impact
An attacker can execute arbitrary JavaScript in the victim's browser, enabling session theft, credential capture, or actions performed as the victim. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through an AJAX request to the plugin's install_online_preset handler; no authentication is required, but the victim must be tricked into submitting the crafted request (UI:R).
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.47 (98.8th percentile) and both references are tagged Exploit, indicating public exploit detail exists. No ransomware usage is documented.
What to do
- Update KingComposer to a version later than 2.9.4, or remove the plugin if it is no longer maintained.
- If patching is not immediately possible, disable or restrict the install_online_preset AJAX action.
- Deploy a WAF rule blocking base64-encoded script payloads in the kc-online-preset-data parameter.
- Apply output encoding and input validation to the kc-online-preset-data parameter in any custom code.
- Restrict administrative and editor access to trusted users to reduce the pool of potential victims.
Detection
- Search web and proxy logs for POST requests to admin-ajax.php with action=install_online_preset and a kc-online-preset-data parameter.
- Inspect kc-online-preset-data values for base64 strings that decode to script tags or JavaScript.
- Alert on unexpected outbound requests or script execution originating from WordPress admin pages.
- Monitor for plugin version 2.9.4 or earlier across managed WordPress instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.wordfence.com/blog/2020/07/xss-flaw-impacting-100000-sites-patched-in-kingcomposer/ | ExploitThird Party Advisory |
| https://www.wordfence.com/blog/2020/07/xss-flaw-impacting-100000-sites-patched-in-kingcomposer/ | ExploitThird Party Advisory |
Track CVE-2020-15299 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-15299), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.