The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.
History

Wed, 04 Jun 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Cozmoslabs
Cozmoslabs profile Builder
Weaknesses CWE-79
CPEs cpe:2.3:a:cozmoslabs:profile_builder:*:*:*:*:*:wordpress:*:*
Vendors & Products Cozmoslabs
Cozmoslabs profile Builder

Tue, 20 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.
Title Profile Builder <= 3.12.0 - Admin+ Stored Cross Site Scripting
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:07:09.159Z

Updated: 2025-05-20T19:23:48.654Z

Reserved: 2024-07-11T21:35:46.026Z

Link: CVE-2024-6708

cve-icon Vulnrichment

Updated: 2025-05-19T20:26:32.635Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:55.860

Modified: 2025-06-04T20:09:28.377

Link: CVE-2024-6708

cve-icon Redhat

No data.