cozmoslabs Vulnerabilities and Affected Products
Vulnerabilities associated with profile_builder.
Products
Clear product- User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor11 vulnerabilities
- Paid Member Subscriptions10 vulnerabilities
- Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction7 vulnerabilities
- Profile Builder Pro6 vulnerabilities
- profile_builder6 vulnerabilities
- Profile Builder3 vulnerabilities
- paid_member_subscriptions2 vulnerabilities
- TranslatePress2 vulnerabilities
- TranslatePress – Translate Multilingual sites with AI Translation2 vulnerabilities
- User Profile Picture2 vulnerabilities
- WP Webhooks2 vulnerabilities
- Profile Builder – User Profile & User Registration Forms1 vulnerability
- Profile Builder – User Profile & User Registration Forms (WordPress plugin)1 vulnerability
- user_profile_picture1 vulnerability
- WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-15030CRITICAL | User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password ResetThe User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account CWE-269Feb 2, 2026 | CVSS9.8v3.1 | EPSS0.487% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6695CRITICAL | profile-builder <= 3.11.8 - Unauthenticated Privilege Escalationit's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process. | CVSS9.8v3.1 | EPSS0.796% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6366CRITICAL | User Profile Builder < 3.11.8 - Unauthenticated Media UploadThe User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP. | CVSS9.1v3.1 | EPSS29% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-31341MEDIUM | WordPress User Profile Builder plugin <= 3.11.2 - Bypass Vulnerability vulnerabilityInsufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2. CWE-345May 17, 2024 | CVSS5.3v3.1 | EPSS0.223% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0653MEDIUM | Profile Builder – User Profile & User Registration Forms <= 3.6.1 Reflected Cross-Site ScriptingThe Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1. | CVSS6.1v3.1 | EPSS2.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-24527CRITICAL | Profile Builder < 3.4.9 - Admin Access via Password ResetThe User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example. | CVSS9.8v3.1 | EPSS7.63% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |