S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0653 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Profile Builder – User Profile & User Registration Forms plugin for Wordpress affects v. through 3.6.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0653
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Profile Builder – User Profile & User Registration Formsby Cozmoslabs
3.6.1
Updated Aug 22, 2026View on NVD →
Detail

The Profile Builder – User Profile & User Registration Forms plugin is a WordPress plugin that is widely used for creating custom user registration forms on websites. It provides an easy and efficient way to manage user profiles and their registration forms. With its simple interface and user-friendly features, this plugin has become an essential tool for website administrators who want to build dynamic user registration forms.

However, the plugin has been recently found to have a critical security vulnerability, CVE-2022-0653, making it prone to Cross-Site Scripting attacks. The vulnerability is due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file. Hackers can exploit this vulnerability to inject arbitrary web scripts onto vulnerable pages, which can enable them to steal sensitive data, bypass authentication systems, or execute malicious code.

When this vulnerability is exploited, it can lead to severe security problems for website owners and their users. For instance, it can allow hackers to steal sensitive user data, such as login credentials and payment information. In addition, it can also lead to defacement of websites, malware infections, and hijacking of user sessions. Moreover, it can negatively impact the reputation and credibility of the affected website, leading to loss of trust and revenue.

In conclusion, it is crucial to take the necessary measures to protect your website from security vulnerabilities. By using pro features of s4e.io, you can easily and quickly learn about vulnerabilities in your digital assets. This platform offers a comprehensive vulnerability scanning solution that can scan your website and highlight areas that need improvement. In addition, it offers a user-friendly dashboard with actionable insights and recommendations to enhance your website's security posture. Therefore, take advantage of it to ensure your website security is top-notch and safe from any breaches.

 

REFERENCES

Solution Advice

To mitigate the risk of this vulnerability, it is essential to take the following precautions:

  • Upgrade to the latest version of the Profile Builder – User Profile & User Registration Forms plugin, which has fixed the vulnerability
  • Regularly update all other plugins, themes, and WordPress core to the latest version
  • Implement a web application firewall (WAF) to intercept and block malicious requests
  • Use Content Security Policy (CSP) to restrict the sources of content that can be loaded on a web page
  • Conduct regular vulnerability scans and penetration testing to detect gaps and vulnerabilities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.