Page 2 of 20 results (0.009 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

29 Sep 2022 — Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on. Una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en el plugin Cozmoslabs Profile Builder versiones anteriores a 3.6.0 incluyéndola en WordPress, permite descargar el archivo JSON y actualizar las opciones. Requiere el complemento de importación y exportación The Profile Builder – User Profile & User ... • https://patchstack.com/database/vulnerability/profile-builder/wordpress-profile-builder-plugin-3-6-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) CWE-862: Missing Authorization •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

09 Mar 2022 — The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed El plugin Profile Builder de WordPress versiones hasta 3.6.8 no sanea ni escapa de los títulos y descripciones de los campos de formulario, lo que podría permitir a usuarios con altos privilegios, como el administrador, llevar a cabo ataques de tipo Cross-Site Scri... • https://plugins.trac.wordpress.org/changeset/2690776 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

17 Feb 2022 — The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1. El plugin Profile Builder - User Profile & User Registration Forms de Wo... • https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2655168%40profile-builder&new=2655168%40profile-builder&sfp_email=&sfph_mail= • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

19 Jul 2021 — The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example. El plugin de WordPress Profile Builder de User Registration & User Profile versiones anteriores a 3.4.9, presenta un bug, permitiendo a cualquier usuario restablecer la contraseña del... • https://wpscan.com/vulnerability/c142e738-bc4b-4058-a03e-1be6fca47207 • CWE-287: Improper Authentication •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

30 Jun 2021 — The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue El plugin de WordPress Profile Builder de User Registration & User Profile versiones anteriores a 3.4.8, no sanea ni escapa de su ajuste "Modify default Redirect Dela... • https://wpscan.com/vulnerability/81e42812-93eb-480d-a2d2-5ba5e02dd0ba • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

13 Jul 2016 — The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues. El plugin profile-builder anterior a la versión 2.4.2 para WordPress tiene múltiples problemas de XSS. • https://wordpress.org/plugins/profile-builder/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

11 Nov 2015 — The profile-builder plugin before 2.2.5 for WordPress has XSS. El plugin generador de perfiles anterior a la versión 2.2.5 para WordPress tiene XSS. The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'loginerror', 'wckerrorfields', 'wckerrormessages', and 'field_name' parameters in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated at... • https://wordpress.org/plugins/profile-builder/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

15 Apr 2015 — The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX. El plugin generador de perfiles anterior a la versión 2.1.4 para WordPress no tiene control de acceso para activar o desactivar complementos a través de AJAX. • https://wordpress.org/plugins/profile-builder/#developers • CWE-284: Improper Access Control •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

30 Oct 2014 — Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter. Múltiples vulnerabilidades de tipo Cross-Site Scripting (XSS) en assets/misc/fallback-page.php en el plugin Profile Builder en versiones anteriores a la 2.0.3 para WordPress permite que los atacantes remotos inyecten scripts web o HTML arbitrari... • https://g0blin.co.uk/cve-2014-8492 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

16 Jul 2014 — The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms. El plugin profile-builder anterior a la versión 1.1.66 para WordPress tiene múltiples problemas XSS en los formularios. • https://wordpress.org/plugins/profile-builder/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •