CVE-2022-0653: Profile Builder – User Profile & User Registration Forms <= 3.6.1 Reflected Cross-Site Scripting
The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the siteurl parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-0653.
What is the severity of CVE-2022-0653?
The severity of CVE-2022-0653 is medium with a severity score of 6.1.
Which software version is affected by CVE-2022-0653?
The Cozmoslabs Profile Builder WordPress plugin version up to and including 3.6.1 is affected by CVE-2022-0653.
How does this vulnerability manifest?
This vulnerability manifests as a Cross-Site Scripting (XSS) issue due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file.
What can an attacker do with this vulnerability?
An attacker can exploit this vulnerability to inject arbitrary web scripts onto a targeted website.