PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2022-0653

6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.
Description

The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
profile builder – user profile & user registration forms
Updated Sep 26, 2026View on NVD →
S4E scanner

CVE-2022-0653 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Profile Builder – User Profile & User Registration Forms plugin for Wordpress affects v. through 3.6.1.

Used 2.3k times · 5.9k assets checked · url

CVE history: profile builder – user profile & user registration forms

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →