Record summary

CVE-2022-0653 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Profile Builder – User Profile & User Registration Forms

Browse Cozmoslabs / Profile Builder – User Profile & User Registration Forms
CVE List3.6.1 to ≤ 3.6.1affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMWordpress Profile Builder Plugin Cross-Site ScriptingCVSS 6.1

The Profile Builder User Profile & User Registration Forms WordPress plugin is vulnerable to cross-site scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1..

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.

Remediation

Upgrade to version 3.6.5 or later.

WeaknessesCWE-79
AuthorsdhiyaneshDk
Template tagscvecve2022wordpressxsswp-plugincozmoslabsvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:cozmoslabs:profile_builder:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3