CVE-2021-24448: Profile Builder < 3.4.8 - Authenticated Stored XSS
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfilteredhtml capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue
Other sources
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfilteredhtml capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24448?
CVE-2021-24448 is a vulnerability in the User Registration & User Profile - Profile Builder WordPress plugin before version 3.4.8.
What is the severity rating of CVE-2021-24448?
CVE-2021-24448 has a severity rating of medium (4.8).
How does CVE-2021-24448 affect the User Registration & User Profile - Profile Builder WordPress plugin?
CVE-2021-24448 allows high privilege users to inject JavaScript code in the 'Modify default Redirect Delay timer' setting, even when unfiltered_html capability is disallowed, leading to an authentication bypass vulnerability.
Is there a fix available for CVE-2021-24448?
Yes, upgrading to version 3.4.8 of the User Registration & User Profile - Profile Builder WordPress plugin fixes the vulnerability.
Where can I find more information about CVE-2021-24448?
More information about CVE-2021-24448 can be found at the following reference: https://wpscan.com/vulnerability/81e42812-93eb-480d-a2d2-5ba5e02dd0ba