The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
We have discovered 7,452 live websites that are affected by CVE-2022-4698.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 7,452 live websites (13.42% of ProfilePress install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 61 versions ( 53.98% of all versions) |
![]() | 2,561 websites |
![]() | 1,104 websites |
![]() | 696 websites |
![]() | 375 websites |
![]() | 248 websites |
![]() | 219 websites |
![]() | 188 websites |
![]() | 183 websites |
![]() | 165 websites |
![]() | 161 websites |
.com | 3,399 websites |
.de | 314 websites |
.org | 307 websites |
.net | 266 websites |
.com.br | 250 websites |
.jp | 231 websites |
.ru | 200 websites |
.pl | 189 websites |
.it | 138 websites |
.co.uk | 122 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.com | ![]() | *,*** | |
*********.com | ![]() | **,*** | |
****************.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
***************.net | ![]() | **,*** | |
************.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
***********.****.org | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
*********.net | ![]() | **,*** |
FAQ