User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor, CVE-2022-0884
- CVE, Research URL
- Home page URL
- Application
-
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
- Published on
- Apr 04, 2022
- Research Description
- The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed
- Affected versions
-
Min -, max 1.1.60.
- Status
-
vulnerable