CVE-2022-0653 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Profile Builder – User Profile & User Registration Forms plugin for Wordpress affects v. through 3.6.1.


The Profile Builder – User Profile & User Registration Forms plugin is a WordPress plugin that is widely used for creating custom user registration forms on websites. It provides an easy and efficient way to manage user profiles and their registration forms. With its simple interface and user-friendly features, this plugin has become an essential tool for website administrators who want to build dynamic user registration forms.

However, the plugin has been recently found to have a critical security vulnerability, CVE-2022-0653, making it prone to Cross-Site Scripting attacks. The vulnerability is due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file. Hackers can exploit this vulnerability to inject arbitrary web scripts onto vulnerable pages, which can enable them to steal sensitive data, bypass authentication systems, or execute malicious code.

When this vulnerability is exploited, it can lead to severe security problems for website owners and their users. For instance, it can allow hackers to steal sensitive user data, such as login credentials and payment information. In addition, it can also lead to defacement of websites, malware infections, and hijacking of user sessions. Moreover, it can negatively impact the reputation and credibility of the affected website, leading to loss of trust and revenue.

