First published: Mon Apr 04 2022(Updated: )
The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cozmoslabs Profile Builder | <3.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of the Profile Builder WordPress plugin vulnerability is CVE-2022-0884.
The severity of CVE-2022-0884 is medium.
The affected software is the Profile Builder WordPress plugin version up to 3.6.8.
An attacker could perform Cross-Site Scripting attacks using CVE-2022-0884.
To fix the vulnerability, update the Profile Builder WordPress plugin to version 3.6.8 or higher.