First published: Thu Feb 24 2022(Updated: )
The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cozmoslabs Profile Builder | <=3.6.1 |
Update to version 3.6.2, or newer.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-0653.
The severity of CVE-2022-0653 is medium with a severity score of 6.1.
The Cozmoslabs Profile Builder WordPress plugin version up to and including 3.6.1 is affected by CVE-2022-0653.
This vulnerability manifests as a Cross-Site Scripting (XSS) issue due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file.
An attacker can exploit this vulnerability to inject arbitrary web scripts onto a targeted website.