{"error":0,"message":null,"data":{"name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor","plugin":"profile-builder","link":"https:\/\/wordpress.org\/plugins\/profile-builder\/","latest":"1789381980","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"765368de181de85edcefa2125145f8544879e2493947bcbd6a3225bf25f69581","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.6.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0653","name":"CVE-2022-0653","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0653","description":"[en] The Profile Builder \u2013 User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~\/assets\/misc\/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.","date":"2022-02-24"},{"id":"c77e38b7b3e42e32adbd3b0ffad9da5e3dca6b6d","name":"WordPress Profile Builder plugin <= 3.6.1 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-3-6-1-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by Chloe Chamberland (Wordfence) in WordPress Profile Builder plugin (versions <= 3.6.1).","date":"2022-02-17"},{"id":"36f4b453c93573e40b0245d8bb3567262f250db5","name":"Profile Builder - User Profile & User Registration Forms <= 3.6.1 - Cross-Site Scripting via site_url Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-user-profile-user-registration-forms-361-cross-site-scripting-via-site-url-parameter","description":"The Profile Builder \u2013 User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~\/assets\/misc\/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.","date":"2022-02-17"},{"id":"656c368a-80bf-44c9-8382-e920b335b921","name":"Profile Builder &lt; 3.6.2 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/656c368a-80bf-44c9-8382-e920b335b921","description":"The plugin does not properly sanitise and escape the site_url parameter before outputting it back in an href attribute, leading to a Reflected Cross-Site Scripting issue","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9f18cb97a6cfe0a5dc8291d5a5d1880f1b8e644f6f936286528457dd4d6f4cfd","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24527","name":"CVE-2021-24527","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24527","description":"[en] The User Registration & User Profile \u2013 Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.","date":"2021-08-16"},{"id":"9aef82abef5b08350001899008882d0eb1cebaaf","name":"Profile Builder <= 3.4.8 - Admin Access via Password Reset","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-348-admin-access-via-password-reset","description":"The User Registration & User Profile \u2013 Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.","date":"2021-07-19"},{"id":"c142e738-bc4b-4058-a03e-1be6fca47207","name":"Profile Builder &lt; 3.4.9 - Admin Access via Password Reset","link":"https:\/\/wpscan.com\/vulnerability\/c142e738-bc4b-4058-a03e-1be6fca47207","description":"The plugin has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}]}},{"uuid":"2aa9cbbf5e62eb83ffe47c33e5381d5c2884056055f67988a12d0c84076982da","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.4.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24448","name":"CVE-2021-24448","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24448","description":"[en] The User Registration & User Profile \u2013 Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue","date":"2021-08-02"},{"id":"1cc4b51f0ffc4b6df933b9f0eed3c19c253672a1","name":"WordPress Profile Builder plugin <= 3.4.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-3-4-7-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Akash Rajendra Patil in WordPress Profile Builder plugin (versions <= 3.4.7).","date":"2021-06-30"},{"id":"d6ff467c33c4accf110a12c44c27233fb349ae7d","name":"Profile Builder <= 3.4.7 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-347-authenticated-administrator-stored-cross-site-scripting","description":"The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping on the 'Modify default Redirect Delay timer' setting. This makes it possible for authenticated attackers. with administrator-level privileges or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2021-06-30"},{"id":"81e42812-93eb-480d-a2d2-5ba5e02dd0ba","name":"Profile Builder &lt; 3.4.8 - Authenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/81e42812-93eb-480d-a2d2-5ba5e02dd0ba","description":"The plugin does not sanitise or escape its &#039;Modify default Redirect Delay timer&#039; setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"3876b586d72f21649a983b4a370624520a6b895e6831b061bad9b8a4e2ad0b54","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 2.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-9337","name":"CVE-2015-9337","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-9337","description":"[en] The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.","date":"2019-08-22"},{"id":"89171d3a338a59ef375a08bf92836bfe02070196","name":"Profile Builder <= 2.1.3 - Missing Access Controls","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-213-missing-access-controls","description":"The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.","date":"2015-04-15"},{"id":"291c30b7-c649-4da0-8fcd-89bb124821d1","name":"Profile Builder &lt; 2.1.4 - Missing Access Controls","link":"https:\/\/wpscan.com\/vulnerability\/291c30b7-c649-4da0-8fcd-89bb124821d1","description":"The User Registration &amp; User Profile &ndash; Profile Builder WordPress plugin was affected by a Missing Access Controls security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}]}},{"uuid":"0c6ad69ed9f6548c28f6f90ce771ee86371895dad67ae5c8a71aefd383dd4076","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 1.1.66","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.66","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-10380","name":"CVE-2014-10380","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-10380","description":"[en] The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.","date":"2019-08-21"},{"id":"4677013f6eed88aa3f3e22f5f1275430ffa2ea1f","name":"Profile Builder \u2013 User Profile & User Registration Forms < 1.1.66 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-user-profile-user-registration-forms-1166-cross-site-scripting","description":"The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.","date":"2014-07-16"},{"id":"c123fcce-dcf0-46b0-b5b6-dec9cbcb1f3c","name":"Profile Builder &lt; 1.1.66 - Multiple XSS","link":"https:\/\/wpscan.com\/vulnerability\/c123fcce-dcf0-46b0-b5b6-dec9cbcb1f3c","description":"The User Registration &amp; User Profile &ndash; Profile Builder WordPress plugin was affected by a Multiple XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"54f96a825dfdb4fae3314c269a5f4e9605d919a6e24fe2000aa227309847053e","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 2.4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2016-10911","name":"CVE-2016-10911","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-10911","description":"[en] The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.","date":"2019-08-21"},{"id":"d8d4704e5fa68116ad30ba31268c6393fe1947ee","name":"Profile Builder \u2013 User Profile & User Registration Forms < 2.4.2 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-user-profile-user-registration-forms-242-cross-site-scripting","description":"The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.","date":"2016-07-13"},{"id":"846376e1-a9ee-4779-9535-d45d109c2a24","name":"Profile Builder &lt; 2.4.2 - Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/846376e1-a9ee-4779-9535-d45d109c2a24","description":"The User Registration &amp; User Profile &ndash; Profile Builder WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"30dbd40f217d7731fc70a4ab71b3cbcd2633c0ffc3f6c043fb9c7363c2eaebf9","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 2.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-9328","name":"CVE-2015-9328","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-9328","description":"[en] The profile-builder plugin before 2.2.5 for WordPress has XSS.","date":"2019-08-21"},{"id":"dbf4ce195e0a79464c64ab3470adc8728e8edf43","name":"Profile Builder \u2013 User Profile & User Registration Forms <= 2.2.4 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-user-profile-user-registration-forms-224-reflected-cross-site-scripting","description":"The Profile Builder \u2013 User Profile & User Registration Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'loginerror', 'wckerrorfields', 'wckerrormessages', and 'field_name' parameters in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2015-11-11"},{"id":"a3cdc2fb-e7b4-47e0-aec9-22bf1a65ae0b","name":"Profile Builder &lt; 2.2.5 - XSS","link":"https:\/\/wpscan.com\/vulnerability\/a3cdc2fb-e7b4-47e0-aec9-22bf1a65ae0b","description":"The User Registration &amp; User Profile &ndash; Profile Builder WordPress plugin was affected by a XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"4adbe6741f7129c9bf258b77de4d95f26927b8ed80e46277bef8bb0a4563aad0","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 2.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-8492","name":"CVE-2014-8492","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-8492","description":"[en] Multiple cross-site scripting (XSS) vulnerabilities in assets\/misc\/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.","date":"2017-10-06"},{"id":"1d53ec6f6fe7a62bb4a91c81aaaa82f62f516d91","name":"Profile Builder <= 2.0.2 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-202-reflected-cross-site-scripting","description":"Multiple cross-site scripting (XSS) vulnerabilities in assets\/misc\/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.","date":"2014-10-30"},{"id":"b92bc41d-dc4b-4451-885d-f723808abf0b","name":"Profile Builder &lt; 2.0.3 - Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/b92bc41d-dc4b-4451-885d-f723808abf0b","description":"The User Registration &amp; User Profile &ndash; Profile Builder WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"012b22ff95b959a78a555e3bb05cc4f7ba1b9b29e0c94a48cafa3c82a9564abd","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.6.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0884","name":"CVE-2022-0884","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0884","description":"[en] The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed","date":"2022-04-04"},{"id":"60d33f54a253b06282d4e5bbec28ec87e1bf2b35","name":"WordPress Profile Builder plugin <= 3.6.7 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-3-6-7-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability discovered by Abhinav Porwal in WordPress Profile Builder plugin (versions <= 3.6.7).","date":"2022-03-09"},{"id":"98550f22e85dcfbf6aee2ac59597db11a96dbcc7","name":"Profile Builder <= 3.6.7 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-367-admin-stored-cross-site-scripting","description":"The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed","date":"2022-03-09"},{"id":"af06b96c-105f-429c-b2ad-c8c823897dba","name":"Profile Builder &lt; 3.6.8 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/af06b96c-105f-429c-b2ad-c8c823897dba","description":"The plugin does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"d73a7bd977eb5ccc6b9e627b4d75a76cf5c934fbddbffcba28794ce1b32121f8","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"af5ce9f7426fea73d33d07c3a4b876c92d20068e","name":"WordPress Profile Builder plugin <= 3.3.2 - Authenticated Blind SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-3-3-2-authenticated-blind-sql-injection-sqli-vulnerability","description":"Authenticated Blind SQL Injection (SQLi) vulnerability found by Lenon Leite in WordPress Profile Builder plugin (versions <= 3.3.2).","date":"2020-12-02"}],"impact":[]},{"uuid":"54ef4456181a6ac7e6a42fdf7353a8a357bd8a7cadb479dafe2411d8366257b9","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"87edd3f2d331b49975ec0bbe32b705f1c7f3feb1","name":"WordPress Profile Builder plugin <= 3.1.0 - User Registration With Administrator Role vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-3-1-0-user-registration-with-administrator-role-vulnerability","description":"User Registration With Administrator Role vulnerability found by Noman Riffat in WordPress Profile Builder plugin (versions <= 3.1.0).","date":"2020-02-10"}],"impact":[]},{"uuid":"94907321ec961c581101b82f78dc03dbba23d03e664814885f61432fcd9acf07","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 2.4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1028cb20c74c560b2a71b5c28b28d10d00979bd9","name":"WordPress Profile Builder Plugin <= 2.4.1 - Reflected Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-2-4-1-reflected-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2016-07-13"}],"impact":[]},{"uuid":"4fe6e5d6b946617ae88dbca51c775026a855d7f735e2aa4b05a8173c242c210f","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 2.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"aa18af36027586124d8cb599ca65e9974793afb7","name":"WordPress Profile Builder  Plugin <= 2.4.0 - Privilege Escalation","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-2-4-0-privilege-escalation","description":"This plugin is prone to a privilege escalation vulnerability.\nUpdate this plugin.","date":"2016-07-08"}],"impact":[]},{"uuid":"0710c11fcc59a3f2538fabbf268bc5c526ef92fe53371c38dca70d7612fb5fe7","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 1.1.60","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.60","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9ff3401921b3932664ad4d121482804a45d2635b","name":"WordPress Profile Builder Plugin <= 1.1.59 - BYPASS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-1-1-59-bypass","description":"Because of this vulnerability, an attacker may exploit this issue to reset account passwords for arbitrary users which may aid in further attacks.\nUpdate the plugin.","date":"2014-08-01"}],"impact":[]},{"uuid":"aa5f8ab8e550cba1cba85996882006fbe3ede60bb5e21b52bfe1aa2f748a22b8","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-36915","name":"CVE-2021-36915","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-36915","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on.","date":"2022-10-11"},{"id":"3749bccd879fc0aa9c9b5a0f22e4920ff1a7d0b8","name":"WordPress Profile Builder plugin <= 3.6.0 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-3-6-0-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability was discovered by mirphak (Patchstack Alliance) in the WordPress Profile Builder plugin (versions <= 3.6.0).\nUpdate the WordPress Profile Builder plugin to the latest available version (at least 3.6.1).","date":"2022-09-29"},{"id":"1e87f9d2a746d79eee337c456c429b9635f0d02f","name":"Profile Builder \u2013 User Profile & User Registration Forms <= 3.6.4 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-user-profile-user-registration-forms-364-cross-site-request-forgery","description":"The Profile Builder \u2013 User Profile & User Registration Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.4. This is due to missing nonce validation on the wppb_pbie_import() & wppb_pbie_export_our_json() functions. This makes it possible for unauthenticated attackers to import and export plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2022-09-29"},{"id":"e6091de1-f2c1-45fe-8221-d55526c7faf6","name":"Profile Builder &lt; 3.6.1 - Settings Import via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/e6091de1-f2c1-45fe-8221-d55526c7faf6","description":"The plugin does not have CSRF check in place when importing settings, which could allow attackers to make a logged in admin import arbitrary settings via a CSRF attack when the Import and Export add-on is active","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"h","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"4.2","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"4.2","severity":"medium","av":"network","ac":"high","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"55d99a1981d80a8f022f9ae7ad81f1c113e7e0b22deef035c4fe7a62fba29de1","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4295aa5025a5e10f7789cad9b3c1259736aba758","name":"Profile Builder\/Profile Builder Pro <= 3.3.2 - Authenticated Blind SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/profile-builderprofile-builder-pro-332-authenticated-blind-sql-injection","description":"The Profile Builder\/Profile Builder Pro plugins for WordPress is vulnerable to blind SQL Injection via multiple parameters in versions up to, and including, 3.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2020-12-04"}],"impact":[]},{"uuid":"2243368b044f7174d05fadc229a33867e8143eceb4d1b3e36aa2b4c546f67d84","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"efa873ef6d772eb505b9f5f80b40fdf015200a48","name":"Profile Builder <= 3.1.0 - Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/profile-builder-310-privilege-escalation","description":"The Profile Builder and Profile Builder Pro plugin versions up to and including 3.1.0 allows unauthenticated attackers to gain administrator-level permissions by registering users on a vulnerable site and assigning their own role.","date":"2020-02-13"}],"impact":[]},{"uuid":"17b6e9e155c10c928a7ace32db6f53d57dcf19b962956330dc8728a87bd170ae","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 2.5.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.5.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"395970d4daacd183cc74a0b1173a230436655559","name":"Profile Builder < 2.5.8 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-258-cross-site-scripting","description":"The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018wppb_general_settings[minimum_password_length]\u2019 parameter in versions before 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with high privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2017-03-10"}],"impact":[]},{"uuid":"c4bcddd6ec9b9f789268beb7dbdcfb9897c2eaa54116fc4e5481f9a292d5c3cc","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 2.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7ab9cafcaf741065f77bfe592e93f5bc5a7a00c3","name":"Profile Builder <= 2.4.0 - Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-240-privilege-escalation","description":"The Profile Builder plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.4.0.  This makes it possible for subscriber-level attackers to elevate user roles to administrative levels, giving them full control of the website.  This vulnerability only impacts websites that have registration enabled, but given that the plugin functionality is directly related to registration it is likely that the majority of websites with the plugin installed are effected.","date":"2016-07-07"}],"impact":[]},{"uuid":"ac126636e4e88fcbc29ec1d17721b8f175d10b01410d347437d560e0758e017e","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 1.1.60","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.60","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e89cfe903ca649503e8a4498e7750a50599a75c7","name":"Profile Builder \u2013 User Profile & User Registration Forms Plugin < 1.1.60 - Authentication Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-user-profile-user-registration-forms-plugin-1160-authentication-bypass","description":"The Profile Builder \u2013 User Profile & User Registration Forms Plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.1.59. This is due to a failure to restrict access on the password reset form. This makes it possible for unauthenticated attackers to reset passwords of user accounts, including administrator accounts.","date":"2014-05-06"}],"impact":[]},{"uuid":"d8215b32038d915179e495571b07fd4c2dc1952bc54023b0e015e2920a100915","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-0814","name":"CVE-2023-0814","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-0814","description":"[en] The Profile Builder \u2013 User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This makes it possible for authenticated attackers, with subscriber-level permissions, and above to retrieve sensitive user meta that can be used to gain access to a high privileged user account. This does require the Usermeta shortcode be enabled to be exploited.","date":"2023-02-14"},{"id":"4197256d27312d9fc35593a4fc16bee5faae1b98","name":"Profile Builder \u2013 User Profile & User Registration Forms <= 3.9.0 - Sensitive Information Disclosure via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-user-profile-user-registration-forms-390-sensitive-information-disclosure-via-shortcode","description":"The Profile Builder \u2013 User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This makes it possible for authenticated attackers, with subscriber-level permissions, and above to retrieve sensitive user meta that can be used to gain access to a high privileged user account. This does require the Usermeta shortcode be enabled to be exploited.","date":"2023-02-13"},{"id":"802c973a6aeeba202b6b001db81cf29302eaa970","name":"WordPress  Profile Builder Plugin  <= 3.9.0 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-3-9-0-sensitive-information-disclosure-via-shortcode-vulnerability","description":"Update the WordPress Profile Builder plugin to the latest available version (at least 3.9.1).\nLana Codes discovered and reported this Sensitive Data Exposure vulnerability in WordPress Profile Builder Plugin.  This vulnerability has been fixed in version 3.9.1.","date":"2023-02-14"},{"id":"f8c6f9d8-3885-4eb3-b959-bc370b004983","name":"Profile Builder &lt; 3.9.1 - Subscriber+ Arbitrary User Meta Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/f8c6f9d8-3885-4eb3-b959-bc370b004983","description":"The plugin does not validate the meta values to be retrieved via its user_meta shortcode, which could allow any logged in users, such as subscriber to retrieve sensitive user meta when the user_meta shortcode is enabled","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3ac0d2a303c4f595154ad856ad3c70542f3678ad172efe761b1d6a2f872841c2","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2297","name":"CVE-2023-2297","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2297","description":"[en] The Profile Builder \u2013 User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets  in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (wppb_front_end_password_recovery). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-0814, or another vulnerability like SQL Injection in another plugin or theme installed on the site to successfully exploit this vulnerability.","date":"2023-04-26"},{"id":"8078463b86f931e3dc5c7b53b3fadad4dba58b5a","name":"WordPress  Profile Builder Plugin  <= 3.9.0 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-3-9-0-insecure-password-reset-mechanism-vulnerability","description":"Update the WordPress Profile Builder plugin to the latest available version (at least 3.9.1).\nLana Codes discovered and reported this Sensitive Data Exposure vulnerability in WordPress Profile Builder Plugin.  This vulnerability has been fixed in version 3.9.1.","date":"2023-04-27"},{"id":"442368fa725a9f974b271d02f399544971b75a1b","name":"Profile Builder \u2013 User Profile & User Registration Forms <= 3.9.0 - Insecure Password Reset Mechanism","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-user-profile-user-registration-forms-390-insecure-password-reset-mechnism","description":"The Profile Builder \u2013 User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets  in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (wppb_front_end_password_recovery). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-0814, or another vulnerability like SQL Injection in another plugin or theme installed on the site to successfully exploit this vulnerability.","date":"2023-02-13"},{"id":"7d4a6b1a-047b-4ce7-9055-1f579e4c1fd7","name":"Profile Builder &lt; 3.9.1 - Unauthorised Password Reset","link":"https:\/\/wpscan.com\/vulnerability\/7d4a6b1a-047b-4ce7-9055-1f579e4c1fd7","description":"The plugin does not properly validate the password reset key, which could lead to attackers to reset arbitrary account password and gain access to them using CVE-2023-0814 or other vulnerabilities allowing for the Reser ket retrieval such as SQLi","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"n","score":"8.1","severity":"h","exploitable":"2.8","impact":"5.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:N","score":"8.1","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"none","exploitable":"2.8","impact":"5.2"},"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."},{"cwe":"CWE-620","name":"Unverified Password Change","description":"When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"970998e0007795d6ec7b63aac98d9db3cd29b0a7db922670106e315aa382997f","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3d643b87-0f52-44cc-9630-4e3e59f19373","name":"Profile Builder &lt; 3.5.1 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/3d643b87-0f52-44cc-9630-4e3e59f19373","description":"The plugin does not escape some generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting","date":null}],"impact":[]},{"uuid":"d6caf711da398889e178916c99de1d7f981ffd5148f7a56849c571e9cf8c6ccb","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c66ca449-600d-46ba-bb27-1ab5699dd4a4","name":"Profile Builder &amp; Profile Builder Pro &lt; 3.3.3 - Authenticated Blind SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/c66ca449-600d-46ba-bb27-1ab5699dd4a4","description":"The orderby parameter of the wp-admin\/users.php?page=unconfirmed_emails&amp;orderby=email&amp;order=asc page, which is available when the &quot;Email confirmation&quot; setting of the plugin is activated (default is off), is not properly sanitised and validated before being concatenated in a SQL statement, leading to an SQL injection. The issue is exploitable by high privilege users such as administrators.","date":null}],"impact":[]},{"uuid":"0bb1a617124a392d72de1535eb64c117ff740247af5ecfc853d889564114c6c3","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e83e1a6d-2259-461e-879f-7f977cdf09f0","name":"Profile Builder and Profile Builder Pro &lt; 3.1.1 - User Registration With Administrator Role","link":"https:\/\/wpscan.com\/vulnerability\/e83e1a6d-2259-461e-879f-7f977cdf09f0","description":"The plugin is affected by a broken authentication vulnerability, allowing unauthenticated users to register or edit their account and gain the Administrator role using the plugin&#039;s forms.\r\n\r\nThe vulnerability only exists in the Plugin&#039;s own generated Registration Form or Profile Edit Form. This means if the blog is using shortcode [wppb-register] or [wppb-edit-profile] then it is vulnerable. This is very obvious shortcode which holds the basic functionality of the plugin so admin must be using it 90% of time if installed. If blog isn&#039;t using [wppb-register] but using [wppb-edit-profile] then vulnerability is still valid if Registration is enabled. CVSS Score of the vulnerability is 9.","date":null}],"impact":[]},{"uuid":"11b04ae768fb34657b03160c6e7c77e2bb3aac21feee90c3fe0ed5cd698f1ef6","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 2.5.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.5.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7f90fb9a-65e7-4361-841a-5db40e195d8a","name":"Profile Builder &lt; 2.5.8 - Authenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/7f90fb9a-65e7-4361-841a-5db40e195d8a","description":"Stored Cross-Site Scripting (XSS) in field minimum password length.","date":null}],"impact":[]},{"uuid":"612420c87816f33de73d381e8550d6b22a90dc0551fea2f018dfaddcdbfdedf5","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 2.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3c5bb7e1-8d1c-4efc-a76b-1c7c73b449f3","name":"Profile Builder &lt; 2.4.1 - Privilege Escalation","link":"https:\/\/wpscan.com\/vulnerability\/3c5bb7e1-8d1c-4efc-a76b-1c7c73b449f3","description":"The User Registration &amp; User Profile &ndash; Profile Builder WordPress plugin was affected by a Privilege Escalation security vulnerability.","date":null}],"impact":[]},{"uuid":"3d3e6befc6c13334e3de169c7ae7c63d335a3946eb4a640c08d100d75f078d81","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 1.1.60","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1.60","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4f4054e7-8350-499e-9418-7cf59784e357","name":"Profile Builder &lt; 1.1.60 - Password Recovery Bypass","link":"https:\/\/wpscan.com\/vulnerability\/4f4054e7-8350-499e-9418-7cf59784e357","description":"The User Registration &amp; User Profile &ndash; Profile Builder WordPress plugin was affected by a Password Recovery Bypass security vulnerability in the front-end\/wppb.recover.password.php file.","date":null}],"impact":[]},{"uuid":"ffa831d6d98c4651a4e51a65578db676a704cbba722a017dcabdbf094805f023","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.9.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5bc6a7ab0272de2a9d6f14639f3b7733867098a1","name":"Profile Builder <= 3.9.7 - Missing Authorization to Initial Page Creation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-397-missing-authorization-to-initial-page-creation","description":"The Profile Builder plugin for WordPress is vulnerable to unauthorized page creation due to a missing capability check on the wppb_create_form_pages() function called via an admin_init action in versions up to, and including, 3.9.7. This makes it possible for unauthenticated attackers to trigger the initial page creation to support the plugin.","date":"2023-08-08"},{"id":"CVE-2023-4059","name":"CVE-2023-4059","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-4059","description":"[en] The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog","date":"2023-09-04"},{"id":"fc719d12-2f58-4d1f-b696-0f937e706842","name":"Profile Builder &lt; 3.9.8 - Unauthenticated Plugin&#039;s Pages Creation","link":"https:\/\/wpscan.com\/vulnerability\/fc719d12-2f58-4d1f-b696-0f937e706842","description":"The plugin lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"aff52a38695335770888af62a0fc31f244b76d01eea8806a597050e8ca07c316","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.9.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fd02b48ed9381f4954fac5672cb7e7f737dc2f3b","name":"WordPress  Profile Builder Plugin  < 3.9.8 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-3-9-7-missing-authorization-to-initial-page-creation-vulnerability","description":"Update the WordPress Profile Builder plugin to the latest available version (at least 3.9.8).\nWordFence discovered and reported this Broken Access Control vulnerability in WordPress Profile Builder Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.9.8.","date":"2023-08-09"}],"impact":[]},{"uuid":"6bb79e358596d2cff56570dccae3eedc4a383dba5e842dad6e85af54979339b8","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.10.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0099c95ee992dadca5c150f1f452318aba172776","name":"Profile Builder <= 3.10.3 - Cross-Site Request Forgery via pms-cross-promotion.php","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-3104-cross-site-request-forgery-via-pms-cross-promotionphp","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.10.3. This is due to missing or incorrect nonce validation on the wppb_activate_pms_plugin and wppb_deactivate_pms_plugin functions. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-11-07"},{"id":"CVE-2023-47669","name":"CVE-2023-47669","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47669","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin <=\u00a03.10.3 versions.","date":"2023-11-13"},{"id":"53ea6be85a568f5eb823a93539023ce0a5232aa6","name":"WordPress  Profile Builder Plugin  <= 3.10.3 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-user-profile-builder-plugin-3-10-3-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress Profile Builder plugin to the latest available version (at least 3.10.4).\nBrandon Roldan discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Profile Builder Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.10.4.","date":"2023-11-08"},{"id":"6b6e896d-eefb-4397-87a7-b92d90d5ea01","name":"Profile Builder &lt; 3.10.4 - Plugins Activation\/Deactivation CSRF","link":"https:\/\/wpscan.com\/vulnerability\/6b6e896d-eefb-4397-87a7-b92d90d5ea01","description":"The plugin does not have CSRF checks when activating and deactivating plugins, which could allow attackers to make logged in users perform such actions via CSRF attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"197ffd98778341023dbf7866959d12ae0baf7dde5598016657267aa50ee82c32","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.10.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6504","name":"CVE-2023-6504","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6504","description":"[en] The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wppb_toolbox_usermeta_handler function in all versions up to, and including, 3.10.7. This makes it possible for authenticated attackers, with contributor-level access and above, to expose sensitive information within user metadata.","date":"2024-01-11"},{"id":"fe1e3199c9237fdbeddcdddee92f7e710d962cfc","name":"Profile Builder <= 3.10.7 - Insecure Direct Object Reference to Sensitive Information Exposure via user_meta Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-3107-insecure-direct-object-reference-to-sensitive-information-exposure-via-user-meta-shortcode","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wppb_toolbox_usermeta_handler function in all versions up to, and including, 3.10.7. This makes it possible for authenticated attackers, with contributor-level access and above, to expose sensitive information within user metadata.","date":"2024-01-05"},{"id":"1cafa9f850425c5e90a9adb69b1be42ee5982765","name":"WordPress  Profile Builder Plugin  <= 3.10.7 is vulnerable to Insecure Direct Object References (IDOR)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-profile-builder-plugin-3-10-7-insecure-direct-object-reference-to-sensitive-information-exposure-via-user-meta-shortcode-vulnerability","description":"Update the WordPress Profile Builder plugin to the latest available version (at least 3.10.8).\nFrancesco Carlucci discovered and reported this Insecure Direct Object References (IDOR) vulnerability in WordPress Profile Builder Plugin. An insecure direct object reference vulnerability could allow a malicious actor to bypass authorization, authentication, access sensitive files\/folders or interact with the database.  This vulnerability has been fixed in version 3.10.8.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-08"},{"id":"a021f0cd-da5b-4f88-8726-d412371f67f0","name":"Profile Builder &lt; 3.10.8 - Contributor+ User Metadata Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/a021f0cd-da5b-4f88-8726-d412371f67f0","description":"The plugin is vulnerable to unauthorized access of data due to a missing capability check on the wppb_toolbox_usermeta_handler function allowing authenticated attackers, with contributor-level access and above, to expose sensitive information within user metadata.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ddbeab97701ffa5ae4c331089e9193145b0c522a602ccaba09a7ceab9faeb1ef","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.10.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-0324","name":"CVE-2024-0324","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-0324","description":"[en] The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all versions up to, and including, 3.10.8. This makes it possible for unauthenticated attackers to enable or disable the 2FA functionality present in the Premium version of the plugin for arbitrary user roles.","date":"2024-02-05"},{"id":"49c51651a95c1112fe678d4cdf9421b2dd02538a","name":"User Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-3108-missing-authorization-to-plugin-settings-change-via-wppb-two-factor-authentication-settings-update","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all versions up to, and including, 3.10.8. This makes it possible for unauthenticated attackers to enable or disable the 2FA functionality present in the Premium version of the plugin for arbitrary user roles.","date":"2024-01-16"},{"id":"55d6044ed7c8b8255b69336a5adae6737101b01b","name":"WordPress  Profile Builder Plugin  <= 3.10.8 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-user-profile-builder-plugin-3-10-8-missing-authorization-to-plugin-settings-change-vulnerability","description":"Update the WordPress Profile Builder plugin to the latest available version (at least 3.10.9).\nkodaichodai discovered and reported this Broken Access Control vulnerability in WordPress Profile Builder Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.10.9.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-16"},{"id":"b332ba23-7ec3-48f1-8090-4158ca3ba231","name":"User Profile Builder &lt; 3.10.9 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update","link":"https:\/\/wpscan.com\/vulnerability\/b332ba23-7ec3-48f1-8090-4158ca3ba231","description":"The plugin is vulnerable to unauthorized modification of data due to a missing capability check on the &#039;wppb_two_factor_authentication_settings_update&#039; function in all versions up to, and including, 3.10.8. This makes it possible for unauthenticated attackers to enable or disable the 2FA functionality present in the Premium version of the plugin for arbitrary user roles.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"bd1214996c396ddffe1038bee9bf6c3abf7048411790c6f506f6b70ebd0aac9f","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.11.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.11.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-31341","name":"CVE-2024-31341","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-31341","description":"[en] Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n\/a through 3.11.2.","date":"2024-05-17"},{"id":"9b2c8f4a20713cc666bc8cfc7c832aa9da52e47c","name":"WordPress  Profile Builder Plugin    <= 3.11.2 is vulnerable to Bypass Vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-user-profile-builder-plugin-3-11-2-bypass-vulnerability-vulnerability","description":"Update the WordPress Profile Builder plugin to the latest available version (at least 3.11.3).\nAnanda Dhakal (Patchstack) discovered and reported this Bypass Vulnerability vulnerability in WordPress Profile Builder Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has been fixed in version 3.11.3.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"3f7dfb13af8f93312dcd549f3c540101466962ec","name":"Profile Builder <= 3.11.2 - Restricted Email Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-3112-restricted-email-bypass","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to restricted email domain bypass in all versions up to, and including, 3.11.2. This makes it possible for unauthenticated attackers to register with emails that are restricted.","date":"2024-04-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-345","name":"Insufficient Verification of Data Authenticity","description":"The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"83d2dbe1135714a38de8167d57152e7b504f1aadc943368e19f9c6920ba4c34c","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.11.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.11.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6695","name":"CVE-2024-6695","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6695","description":"[en] it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.","date":"2024-07-31"},{"id":"6186dbd286b3cffa267fe00a1cec4530569b375b","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.8 - Authentication Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-beautiful-user-registration-forms-user-profiles-user-role-editor-3118-authentication-bypass","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to authenticated bypass in all versions up to, and including, 3.11.8. This is due to the plugin not properly handling the user registration flow and utilizing different functionality at different stages of the process. This makes it possible for unauthenticated attackers to login as other users granted they know the user's email address.","date":"2024-07-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."},{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"c5e026973db831627a63dd97a64900c871649d99715f6ecb1e8493c9bc5b4c86","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.11.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.11.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6366","name":"CVE-2024-6366","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6366","description":"[en] The User Profile Builder  WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.","date":"2024-07-29"},{"id":"f9ff12435496ea918ea5198eecc44b1e7c66a35e","name":"WordPress Profile Builder Plugin < 3.11.8 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-user-profile-builder-plugin-3-11-8-unauthenticated-media-upload-vulnerability","description":"<p>WordPress Profile Builder Plugin < 3.11.8 is vulnerable to Broken Access Control<\/p><p>Software: Profile Builder<\/p><p>Link: https:\/\/wordpress.org\/plugins\/profile-builder\/#developers<\/p><p>Affected Version < 3.11.8<\/p><p>Fixed in version 3.11.8 <\/p>","date":"2024-07-29"},{"id":"d21f7a9239aaf4b5b6967c6ce134390a33112e47","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.7 - Missing Authorization to Unauthenticated Media Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-beautiful-user-registration-forms-user-profiles-user-role-editor-3117-missing-authorization-to-unauthenticated-media-upload","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized file uplloads due to a missing capability check on the wppb_upload_file_type() function in all versions up to, and including, 3.11.7. This makes it possible for unauthenticated attackers to upload arbitrary media files via the async upload functionality.","date":"2024-07-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"n","score":"9.1","severity":"c","exploitable":"3.9","impact":"5.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N","score":"9.1","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"none","exploitable":"3.9","impact":"5.2"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"79824b0a889a748118eeb7ca6a3fe27e0bed71b78ccd78212749066a33afb6c4","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.13.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.13.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-12738","name":"CVE-2024-12738","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-12738","description":"[en] The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user meta parameters in all versions up to, and including, 3.12.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page and clicks a link to show user meta.","date":"2025-01-07"},{"id":"55b3463be22bc8f37fe638528eb8c703848dfb93","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.9 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-beautiful-user-registration-forms-user-profiles-user-role-editor-3129-unauthenticated-stored-cross-site-scripting","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user meta parameters in all versions up to, and including, 3.12.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page and clicks a link to show user meta.","date":"2025-01-06"},{"id":"77f07debb6b9bcba8f76760f1951a4c31a677305","name":"WordPress Profile Builder Plugin <= 3.12.9 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/profile-builder\/vulnerability\/wordpress-user-profile-builder-plugin-3-12-9-unauthenticated-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Profile Builder Plugin <= 3.12.9 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Profile Builder<\/p><p>Fixed in version 3.13.0 <\/p><p>Affected Version <= 3.12.9<\/p><p>CVE: CVE-2024-12738<\/p>","date":"2025-01-07"},{"id":"EUVD-2024-51080","name":"EUVD-2024-51080","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-51080","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user meta parameters in all versions up to, and including, 3.12.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page and clicks a link to show user meta.","date":"2025-01-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.004"}},{"uuid":"76e90e17c811b811345462ddb28245d1937aaea9239735aa1d6c283f1431ef2a","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.13.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.13.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-2314","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-2314","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.\r\nThe issue was partially patched in version 3.13.6 of the plugin, and fully patched in 3.13.7.","date":"0000-00-00"},{"id":"3fb5b68c44e3762803cdd142b9119762e3e5bebe","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-beautiful-user-registration-forms-user-profiles-user-role-editor-3135-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.\r\nThe issue was partially patched in version 3.13.6 of the plugin, and fully patched in 3.13.7.","date":"2025-04-15"},{"id":"EUVD-2025-11465","name":"EUVD-2025-11465","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-11465","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.\r\nThe issue was partially patched in version 3.13.6 of the plugin, and fully patched in 3.13.7.","date":"2025-04-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6d0fd64424c4a23ace56662510d6bcd714f5732f977d02e6c17a5a49cde296ee","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.12.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6708","name":"Profile Builder <= 3.12.0 - Admin+ Stored Cross Site Scripting","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6708","description":"The User Profile Builder  WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.","date":"0000-00-00"},{"id":"EUVD-2025-15276","name":"EUVD-2025-15276","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-15276","description":"The User Profile Builder  WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.","date":"2025-05-15"},{"id":"db0531bb8974ff029bbad678e61c7832ef33b70a","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.1 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-beautiful-user-registration-forms-user-profiles-user-role-editor-3121-authenticated-admin-stored-cross-site-scripting","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-08-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"f16fce12b550693f71277e6cdb18a60f6dffc52a6784953a8978d60c663b4236","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.13.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.13.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-4671","name":"Profile Builder <= 3.13.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-4671","description":"The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"7c01aa6f85f06a402d546240a222b12cdaffe032","name":"Profile Builder <= 3.13.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-3138-authenticated-contributor-stored-cross-site-scripting-via-user-meta-and-compare-shortcodes","description":"The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-02"},{"id":"EUVD-2025-16720","name":"EUVD-2025-16720","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-16720","description":"The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"eadb5cad904f015f7d351e8d6cc42b5e763da1c4644b38ce09eab87d69411cd7","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.13.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.13.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-49292","name":"CVE-2025-49292","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-49292","description":"[en] Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder allows Phishing. This issue affects Profile Builder: from n\/a through 3.13.8.","date":"2025-06-06"},{"id":"a33ddba61ae34becf1805826cb80a87c6d455ef9","name":"Profile Builder <= 3.13.8 - Unauthenticated Content Spoofing","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/profile-builder-3138-unauthenticated-content-spoofing","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Content Spoofing in all versions up to, and including, 3.13.8. This makes it possible for unauthenticated attackers to spoof content.","date":"2025-06-05"},{"id":"EUVD-2025-17270","name":"EUVD-2025-17270","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-17270","description":"Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder allows Phishing. This issue affects Profile Builder: from n\/a through 3.13.8.","date":"2025-06-06"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-1284","name":"Improper Validation of Specified Quantity in Input","description":"The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":null,"impact":null},"epss":"0.001"}},{"uuid":"5d9ad0d5ce17c92ae95891cc272482e9f96e040cb48db2bfc82c11a44056d4eb","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.14.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-8896","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-8896","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_communication_preferences[]' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the GDPR Communication Preferences module is enabled and at least one GDPR Communication Preferences field has been added to the edit profile form.","date":"0000-00-00"},{"id":"f9d78519cb41d495eebbe359dbb5cb8938446451","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-beautiful-user-registration-forms-user-profiles-user-role-editor-3143-authenticated-subscriber-stored-cross-site-scripting","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_communication_preferences[]' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the GDPR Communication Preferences module is enabled and at least one GDPR Communication Preferences field has been added to the edit profile form.","date":"2025-08-15"},{"id":"EUVD-2025-25075","name":"EUVD-2025-25075","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-25075","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_communication_preferences[]' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the GDPR Communication Preferences module is enabled and at least one GDPR Communication Preferences field has been added to the edit profile form.","date":"2025-08-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f7b75879b645966261ca6e30be50f6148e97be0f5b6889496548cf161680b5c5","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.14.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13054","name":"CVE-2025-13054","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13054","description":"[en] The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-11-19"},{"id":"fb80cc7ead6fc9e26107a832218ce4a69b7c3150","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-beautiful-user-registration-forms-user-profiles-user-role-editor-3148-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-11-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9fbf073ba1b3eed3a62914aebdd49269a1decec8d5c92f86b6c64592385b64fb","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.15.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.15.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-15030","name":"CVE-2025-15030","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-15030","description":"[en] The User Profile Builder  WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account","date":"2026-02-02"},{"id":"5b67300001b9cf16ad190bfe39415681e6695dec","name":"User Profile Builder <= 3.15.1 - Unauthenticated Privilege Escalation via Account Takeover","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-3151-unauthenticated-privilege-escalation-via-account-takeover","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.15.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.","date":"2026-01-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"6250eb1a8d4f4f06e3d7d6ac15c2caa48ff11e7f44600aa4e1d6b0bc23a07bc7","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.15.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.15.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-3139","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3139","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to reassign ownership of arbitrary posts and attachments by changing 'post_author'.","date":"0000-00-00"},{"id":"cf6c0b08408772900c46b06f26f9fa960f3e419c","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-beautiful-user-registration-forms-user-profiles-user-role-editor-3155-insecure-direct-object-reference-to-authenticated-subscriber-arbitrary-post-author-reassignment-via-avatar-field","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to reassign ownership of arbitrary posts and attachments by changing 'post_author'.","date":"2026-03-30"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"68929f86789fa45e388255d3de0900bcfba5a9b9969b590b7e3a40f26c5f75ab","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.16.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.16.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15368","name":"CVE-2026-15368","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15368","description":"[en] The User Profile Builder  WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration.","date":"2026-08-01"}],"impact":{"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"c2db6989b6d5a35d6bfe5df0793774a7385a0e361d3f158b872f0df7c986e7d6","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.16.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.16.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-66701","name":"CVE-2026-66701","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-66701","description":"[en] Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.","date":"2026-08-06"},{"id":"79f5e9044aefe93a69b110ebe5dd43d23f1b2779","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.16.5 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/16a4665a-df79-4def-8215-df44dffdd332","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.16.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-07-29"},{"id":"ca0c76a3d23f6e2d4ff673b4426de3b9330f1826","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.16.5 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-beautiful-user-registration-forms-user-profiles-user-role-editor-3165-missing-authorization","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.16.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-03-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5475de960302c823e866fff5c0b9e02a76ff9df67c953f1780404f9aba265f15","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.16.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.16.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15826","name":"CVE-2026-15826","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15826","description":"[en] The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check \u2014 when a registration is submitted with a 61\u201370 character username, WordPress core rejects it with a WP_Error object, but absint() coerces that object to the integer 1 before the error check can short-circuit execution, causing the plugin to bind and return a transient-backed autologin nonce tied to user ID 1. This makes it possible for unauthenticated attackers to log in as the site's Administrator account (user ID 1), resulting in full administrative takeover of the site.","date":"2026-08-15"},{"id":"9722b4ccf4cf8edcd0dc6863e73b6d1cefba9924","name":"User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-3164-unauthenticated-authentication-bypass-via-type-confusion-to-administrator-account-takeover-via-username-parameter","description":"The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check \u2014 when a registration is submitted with a 61\u201370 character username, WordPress core rejects it with a WP_Error object, but absint() coerces that object to the integer 1 before the error check can short-circuit execution, causing the plugin to bind and return a transient-backed autologin nonce tied to user ID 1. This makes it possible for unauthenticated attackers to log in as the site's Administrator account (user ID 1), resulting in full administrative takeover of the site.","date":"2026-08-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-704","name":"Incorrect Type Conversion or Cast","description":"The product does not correctly convert an object, resource, or structure from one type to a different type."}]}},{"uuid":"8cf5783a8574fc8ef6b9cc141b98734dbeb3102014f71724244343f1e5f0901b","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 4.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-76548","name":"CVE-2026-76548","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-76548","description":"[en] The User Profile Builder  WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.","date":"2026-08-29"},{"id":"4535710c2f4c7cde97c5b12d2e89be7b848c9339","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor < 4.0.1 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-beautiful-user-registration-forms-user-profiles-user-role-editor-401-missing-authorization","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access in all versions up to 4.0.1. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-08-31"}],"impact":{"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e0b6dc4867446099356b56eaab999aacc97dd3dad1f83fd3fb31505f07a0d994","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 4.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-76547","name":"CVE-2026-76547","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-76547","description":"[en] The User Profile Builder  WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is present in the User Profile Builder  WordPress plugin before 4.0.1 itself, so further impact requires a suitable gadget from another installed User Profile Builder  WordPress plugin before 4.0.1 or .","date":"2026-08-29"},{"id":"53afe8ffc3e183a51288d291238729edd932d815","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor < 4.0.1 - Authenticated (Administrator+) PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-beautiful-user-registration-forms-user-profiles-user-role-editor-401-authenticated-administrator-php-object-injection","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 4.0.1. This is due to deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2026-08-31"}],"impact":{"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"33e57fa488dbdc30b05ceac3e00150655f28d7a424e018ef7e4ae5348967dae8","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 4.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-76546","name":"CVE-2026-76546","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-76546","description":"[en] The User Profile Builder  WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by default.","date":"2026-08-29"},{"id":"261a9866fc2a9829b875184b40780095bc0666f4","name":"User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor < 4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-beautiful-user-registration-forms-user-profiles-user-role-editor-401-authenticated-contributor-stored-cross-site-scripting","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 4.0.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-08-31"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5d069acbf037cc787907ab57048672eaa98ca2ad8ecfb49a2a0f52fcf69207f8","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 4.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-75965","name":"CVE-2026-75965","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-75965","description":"[en] The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode Attribute in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the wppb_toolbox_shortcodes_settings[format-date] option to be set to 'yes' by an administrator for the shortcode to be active and the vulnerability to be exploitable.","date":"2026-09-01"},{"id":"ce90cc6f1fe8cd7cba8858f07162c4ff6e60ffa1","name":"User Profile Builder <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'date' Shortcode Attribute","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-400-authenticated-contributor-stored-cross-site-scripting-via-date-shortcode-attribute","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode Attribute in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the wppb_toolbox_shortcodes_settings[format-date] option to be set to 'yes' by an administrator for the shortcode to be active and the vulnerability to be exploitable.","date":"2026-08-31"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4a04b5f678825f39c1301fc84bc0eb1eb6f16225e6524e01589a90c522202a82","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 4.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-75964","name":"CVE-2026-75964","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-75964","description":"[en] The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload reaches administrators with the manage_options capability when they visit the Users > Unconfirmed Email Addresses list table and interact with row-action links, as the poisoned javascript: href is rendered verbatim into the page HTML by row_actions().","date":"2026-09-01"},{"id":"4ba445274e9416028f8a59d1779c93d790b1ac88","name":"User Profile Builder <= 4.0.0 - Unauthenticated Stored Cross-Site Scripting via 'email' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-400-unauthenticated-stored-cross-site-scripting-via-email-parameter","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload reaches administrators with the manage_options capability when they visit the Users > Unconfirmed Email Addresses list table and interact with row-action links, as the poisoned javascript: href is rendered verbatim into the page HTML by row_actions().","date":"2026-08-31"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a9535c02c257d6705ebcd7a5b464430c513dff9e754109f7f1f8ee4f59bda93d","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] < 3.15.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.15.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-6431","name":"CVE-2026-6431","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-6431","description":"[en] The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-09-07"},{"id":"b4eeb54d431e428648e8a19e7691e8f434180bd8","name":"User Profile Builder <= 3.15.7 - Unauthenticated Stored Cross-Site Scripting via 'Biographical Info' Meta Field","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/profile-builder\/user-profile-builder-3157-unauthenticated-stored-cross-site-scripting-via-biographical-info-meta-field","description":"The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-08-31"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b61fe40a2319ec5bb158667ddcbdd1cdec9ddce4f230f21d7d8bb9b63ffef27d","name":"User Profile Builder &#8211; Beautiful User Registration Forms, User Profiles &amp; User Role Editor [profile-builder] <= 3.16.1 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.16.1","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-82607","name":"CVE-2026-82607","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-82607","description":"[en] A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file \/wp-admin\/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 3.16.2 is sufficient to resolve this issue. It is suggested to upgrade the affected component.","date":"2026-08-31"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L\/E:P\/RL:O\/RC:C","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"7.3","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L\/E:P\/RL:O\/RC:C","score":"7.3","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789024205"}