User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor, e83e1a6d-2259-461e-879f-7f977cdf09f0
- CVE, Research URL
- Home page URL
- Application
-
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
- Published on
- -
- Research Description
- User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.1.1 Profile Builder and Profile Builder Pro < 3.1.1 - User Registration With Administrator Role The plugin is affected by a broken authentication vulnerability, allowing unauthenticated users to register or edit their account and gain the Administrator role using the plugin's forms. The vulnerability only exists in the Plugin's own generated Registration Form or Profile Edit Form. This means if the blog is using shortcode [wppb-register] or [wppb-edit-profile] then it is vulnerable. This is very obvious shortcode which holds the basic functionality of the plugin so admin must be using it 90% of time if installed. If blog isn't using [wppb-register] but using [wppb-edit-profile] then vulnerability is still valid if Registration is enabled. CVSS Score of the vulnerability is 9.
- Affected versions
-
max 3.1.1.
- Status
-
vulnerable