Vulnerabilities > CVE-2021-24955 - Unspecified vulnerability in Profilepress User Registration, Login Form, User Profile & Membership 3.2.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |