CVE-2021-24448

CVE-2021-24448: Profile Builder < 3.4.8 - Authenticated Stored XSS

Vendor Unknown
Product User Registration & User Profile – Profile Builder
Weakness CWE-79 · XSS
Published August 2, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

Key dates

02Disclosure timeline

August 2, 2021 CVE published
August 3, 2024 Record updated