The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user access, such as subscribers, to inject arbitrary web scripts into their profile, in versions up to and including 1.2.7.
History

Thu, 13 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-02-13T20:42:23.285Z

Reserved: 2022-01-14T00:00:00.000Z

Link: CVE-2022-0233

cve-icon Vulnrichment

Updated: 2024-08-02T23:18:42.893Z

cve-icon NVD

Status : Modified

Published: 2022-01-18T17:15:10.523

Modified: 2024-11-21T06:38:11.890

Link: CVE-2022-0233

cve-icon Redhat

No data.