Ultimate Profile Builder < 3.0 - Cross-Site Request Forgery to Cross-Site Scripting
highThe Ultimate Profile Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting via multiple parameters in versions before 3.0 due to insufficient input sanitization and output escaping and missing nonce validation. This makes it possible for unauthenticated attackers to inject ar...
- CVSS:
- 7.1
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- May 7, 2015