Back

MEDIUM

Profile Builder – User Profile & User Registration Forms <= 3.6.1 Reflected Cross-Site Scripting

Published Feb 24, 2022

Description

The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.

Affected products

Remediation

Vendor solution

Update to version 3.6.2, or newer.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Feb 24, 2022
Updated Jan 31, 2025
Reserved Feb 16, 2022
CISA Vulnrichment
Updated Jan 31, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a