User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor, fd02b48ed9381f4954fac5672cb7e7f737dc2f3b
- CVE, Research URL
- Home page URL
- Application
-
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
- Published on
- Aug 09, 2023
- Research Description
- User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.9.8 WordPress Profile Builder Plugin < 3.9.8 is vulnerable to Broken Access Control Update the WordPress Profile Builder plugin to the latest available version (at least 3.9.8). WordFence discovered and reported this Broken Access Control vulnerability in WordPress Profile Builder Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.9.8.
- Affected versions
-
max 3.9.8.
- Status
-
vulnerable