Known CVE
Wordpress Profile Builder Plugin Cross-Site Scripting
The Profile Builder User Profile & User Registration Forms WordPress plugin is vulnerable to cross-site scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1..
CVE-2022-0653
Medium2022CVSS 6.1CWE-79
cve2022 · wordpress · xss · wp-plugin · cozmoslabs · vkev · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website