cleantalk
Vulnerabilities and Security Researches

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor, CVE-2023-4059

CVE, Research URL

CVE-2023-4059

Published on
Sep 04, 2023
Research Description
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog
Affected versions
Min -, max 3.10.4.
Status
vulnerable