cleantalk
Vulnerabilities and Security Researches

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor, CVE-2014-8492

CVE, Research URL

CVE-2014-8492

Published on
Oct 06, 2017
Research Description
Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.
Affected versions
Min -, max 2.0.3.
Status
vulnerable