Profile Builder < 3.6.8 - Admin+ Stored Cross-Site Scripting
CVE-2022-0884
4.8MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 4 April 2022
Summary
The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed
Affected Version(s)
Profile Builder – User Profile & User Registration Forms 3.6.8
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abhinav Porwal