PT-2022-13052 · WordPress · Profilegrid

Big Tiger

·

Published

2022-01-18

·

Updated

2022-01-24

·

CVE-2022-0233

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin versions up to and including 1.2.7
Description The issue arises from insufficient escaping via the pm user avatar and pm cover image parameters in the ~/admin/class-profile-magic-admin.php file, allowing attackers with authenticated user access to inject arbitrary web scripts into their profile.
Recommendations For versions up to and including 1.2.7, update to a version that includes the necessary escaping for the pm user avatar and pm cover image parameters to prevent Stored Cross-Site Scripting. As a temporary workaround, consider restricting access to the ~/admin/class-profile-magic-admin.php file to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0233

Affected Products

Profilegrid