CVE-2021-24448

Severity
4.8MEDIUM
EPSS
0.4%
top 38.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-8j23-c7w9-jxvg: The User Registration & User Profile – Profile Builder WordPress plugin before 32022-05-24
CVEList
Profile Builder < 3.4.8 - Authenticated Stored XSS2021-08-02
CVE-2021-24448 (MEDIUM CVSS 4.8) | The User Registration & User Profil | cvebase.io