Showing 6 vulnerabilities on this page for profile_builder

Signals CISA KEV Ransomware Nuclei
cozmoslabs vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

CWE-269Feb 2, 2026
CVSS9.8v3.1EPSS0.487%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

profile-builder <= 3.11.8 - Unauthenticated Privilege Escalation

it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.

CWE-287CWE-863Jul 31, 2024
CVSS9.8v3.1EPSS0.796%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

User Profile Builder < 3.11.8 - Unauthenticated Media Upload

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

CWE-434CWE-862Jul 29, 20241 related artifact
CVSS9.1v3.1EPSS29%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WordPress User Profile Builder plugin <= 3.11.2 - Bypass Vulnerability vulnerability

Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.

CWE-345May 17, 2024
CVSS5.3v3.1EPSS0.223%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Profile Builder – User Profile & User Registration Forms <= 3.6.1 Reflected Cross-Site Scripting

The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.

CWE-79Feb 24, 20221 related artifact
CVSS6.1v3.1EPSS2.7%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Profile Builder < 3.4.9 - Admin Access via Password Reset

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.

CWE-287Aug 16, 20211 related artifact
CVSS9.8v3.1EPSS7.63%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX