CVE-2022-4698

The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.


We have discovered 7,452 live websites that are affected by CVE-2022-4698.

Test my site




Affected Software

Product  ProfilePress
Category Wordpress Plugins
Vulnerable Domains7,452 live websites (13.42% of ProfilePress install base)
Vulnerable Versions
  • from 0 through 4.5
Vulnerable Versions Count61 versions ( 53.98% of all versions)



Details

  • Published - Dec 23, 2022
  • Updated - Jan 14, 2025

Credits

  • Ivan Kuzymchak (finder)

CVE-2022-4698 usage by Country

United States2,561 websites



Japan1,104 websites
Germany696 websites
France375 websites
Russia248 websites
Poland219 websites
Brazil188 websites
GB183 websites
Spain165 websites
Italy161 websites

CVE-2022-4698 usage by TLD

.com3,399 websites
.de314 websites
.org307 websites
.net266 websites
.com.br250 websites
.jp231 websites
.ru200 websites
.pl189 websites
.it138 websites
.co.uk122 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-4698

Top websites that are affected by CVE-2022-4698. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States*,***
*********.com Japan**,***
****************.com United States**,***
************.com United States**,***
***************.net United States**,***
************.com Japan**,***
*********.com United States**,***
***********.****.org United States**,***
**************.com United States**,***
*********.net United States**,***
See full domain list

FAQ

A total of 7,452 websites have been identified as vulnerable to CVE-2022-4698, discovered through global website indexing conducted by WebTechSurvey.
ProfilePress is susceptible to CVE-2022-4698 vulnerability.
ProfilePress versions before, and including, 4.5 are vulnerable to CVE-2022-4698.