CVE-2021-24527

CRITICAL EXPLOITED NUCLEI

Cozmoslabs Profile Builder < 3.4.9 - Authentication Bypass

Title source: rule

Description

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.

Nuclei Templates (1)

Profile Builder < 3.4.9 - Improper Authentication
CRITICALVERIFIEDby Sourabh-Sahu

Scores

CVSS v3 9.8
EPSS 0.7559
EPSS Percentile 98.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-01-11
CWE
CWE-287
Status published
Products (1)
cozmoslabs/profile_builder < 3.4.9
Published Aug 16, 2021
Tracked Since Feb 18, 2026