First published: Mon Dec 13 2021(Updated: )
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Profilepress User Registration\, Login Form\, User Profile \& Membership | <3.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-24955.
The severity of CVE-2021-24955 is medium with a CVSS score of 6.1.
The User Registration, Login Form, User Profile & Membership WordPress plugin before version 3.2.3 is affected by CVE-2021-24955.
The CWE ID for CVE-2021-24955 is CWE-79.
To fix the CVE-2021-24955 vulnerability, update the User Registration, Login Form, User Profile & Membership WordPress plugin to version 3.2.3 or higher.