User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
critical
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check — when a registration is subm...
- CVSS:
- 9.8
- Affected:
- up to 3.16.4
- Fixed in:
- 3.16.5
- Disclosed:
- Aug 14, 2026
CVE-2026-15826 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.16.5 - Missing Authorization
medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.16.5. This makes it possible for unauthenticated attackers to perform an unauthoriz...
- CVSS:
- 5.3
- Affected:
- up to 3.16.5
- Fixed in:
- 3.16.6
- Disclosed:
- Jul 29, 2026
CVE-2026-66701 on NVD →
Profile Builder <= 3.16.3 - Privilege Escalation to Unauthenticated Account Takeover
high
The Profile Builder plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.16.3. This is due to the target user ID for auto-login after registration being passed as a user-controlled URL parameter (`uid`) with no server-side binding to the issued nonce, allowing any unauthenticat...
- CVSS:
- 7.3
- Affected:
- up to 3.16.3
- Fixed in:
- 3.16.4
- Disclosed:
- Jul 17, 2026
CVE-2026-15368 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field
medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value() function due to missing validation on a user controlled key. This makes it possi...
- CVSS:
- 4.3
- Affected:
- up to 3.15.5
- Fixed in:
- 3.15.6
- Disclosed:
- Mar 30, 2026
CVE-2026-3139 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.15.2
unknown
[en] The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account
- Affected:
- up to 3.15.2
- Fixed in:
- 3.15.2
- Disclosed:
- Feb 2, 2026
CVE-2025-15030 on NVD →
User Profile Builder <= 3.15.1 - Unauthenticated Privilege Escalation via Account Takeover
critical
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.15.1. This is due to the plugin not properly validating a user's identity prior to updating their passwor...
- CVSS:
- 9.8
- Affected:
- up to 3.15.1
- Fixed in:
- 3.15.2
- Disclosed:
- Jan 12, 2026
CVE-2025-15030 on NVD →
User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset
unknown
- Affected:
- 1.1.27 – 3.15.2
- Fixed in:
- 3.15.2
- Disclosed:
- Jan 12, 2026
CVE-2025-15030 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.14.9
unknown
[en] The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supp...
- Affected:
- up to 3.14.9
- Fixed in:
- 3.14.9
- Disclosed:
- Nov 19, 2025
CVE-2025-13054 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supplied...
- CVSS:
- 6.4
- Affected:
- up to 3.14.8
- Fixed in:
- 3.14.9
- Disclosed:
- Nov 18, 2025
CVE-2025-13054 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor < 3.14.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
- Affected:
- up to 3.14.9
- Fixed in:
- 3.14.9
- Disclosed:
- Nov 18, 2025
CVE-2025-13054 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_communication_preferences[]' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. T...
- CVSS:
- 6.4
- Affected:
- up to 3.14.3
- Fixed in:
- 3.14.4
- Disclosed:
- Aug 15, 2025
CVE-2025-8896 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor < 3.14.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting
high
- Affected:
- up to 3.14.4
- Fixed in:
- 3.14.4
- Disclosed:
- Aug 15, 2025
CVE-2025-8896 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.13.9
unknown
[en] Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder allows Phishing. This issue affects Profile Builder: from n/a through 3.13.8.
- Affected:
- up to 3.13.9
- Fixed in:
- 3.13.9
- Disclosed:
- Jun 6, 2025
CVE-2025-49292 on NVD →
Profile Builder <= 3.13.8 - Unauthenticated Content Spoofing
medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Content Spoofing in all versions up to, and including, 3.13.8. This makes it possible for unauthenticated attackers to spoof content.
- CVSS:
- 5.3
- Affected:
- up to 3.13.8
- Fixed in:
- 3.13.9
- Disclosed:
- Jun 5, 2025
CVE-2025-49292 on NVD →
Profile Builder < 3.13.9 - Unauthenticated Content Spoofing
unknown
- Affected:
- up to 3.13.9
- Fixed in:
- 3.13.9
- Disclosed:
- Jun 5, 2025
CVE-2025-49292 on NVD →
Profile Builder <= 3.13.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes
medium
The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 3.13.8
- Fixed in:
- 3.13.9
- Disclosed:
- Jun 2, 2025
CVE-2025-4671 on NVD →
Profile Builder < 3.13.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes
medium
- Affected:
- up to 3.13.9
- Fixed in:
- 3.13.9
- Disclosed:
- Jun 2, 2025
CVE-2025-4671 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13.5 due to insufficient input sanitization and output escaping on user supplied attributes...
- CVSS:
- 6.4
- Affected:
- up to 3.13.6
- Fixed in:
- 3.13.7
- Disclosed:
- Apr 15, 2025
CVE-2025-2314 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor < 3.13.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
- Affected:
- up to 3.13.7
- Fixed in:
- 3.13.7
- Disclosed:
- Apr 15, 2025
CVE-2025-2314 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.13.0
unknown
[en] The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user meta parameters in all versions up to, and including, 3.12.9 due to insufficient input sanitization and output escaping. This makes it po...
- Affected:
- up to 3.13.0
- Fixed in:
- 3.13.0
- Disclosed:
- Jan 7, 2025
CVE-2024-12738 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.9 - Unauthenticated Stored Cross-Site Scripting
medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user meta parameters in all versions up to, and including, 3.12.9 due to insufficient input sanitization and output escaping. This makes it possibl...
- CVSS:
- 6.1
- Affected:
- up to 3.12.9
- Fixed in:
- 3.13.0
- Disclosed:
- Jan 6, 2025
CVE-2024-12738 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor < 3.13.0 - Unauthenticated Stored Cross-Site Scripting
high
- Affected:
- up to 3.13.0
- Fixed in:
- 3.13.0
- Disclosed:
- Jan 6, 2025
CVE-2024-12738 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenti...
- CVSS:
- 4.4
- Affected:
- up to 3.12.1
- Fixed in:
- 3.12.2
- Disclosed:
- Aug 13, 2024
CVE-2024-6708 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.11.9
unknown
[en] it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.
- Affected:
- up to 3.11.9
- Fixed in:
- 3.11.9
- Disclosed:
- Jul 31, 2024
CVE-2024-6695 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.11.8
unknown
[en] The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.
- Affected:
- up to 3.11.8
- Fixed in:
- 3.11.8
- Disclosed:
- Jul 29, 2024
CVE-2024-6366 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.8 - Authentication Bypass
critical
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.11.8. This is due to the plugin not properly handling the user registration flow and utilizing different functionality at dif...
- CVSS:
- 9.8
- Affected:
- up to 3.11.8
- Fixed in:
- 3.11.9
- Disclosed:
- Jul 10, 2024
CVE-2024-6695 on NVD →
profile-builder < 3.11.9 - Unauthenticated Privilege Escalation
critical
- Affected:
- up to 3.11.9
- Fixed in:
- 3.11.9
- Disclosed:
- Jul 10, 2024
CVE-2024-6695 on NVD →
Profile Builder <= 3.12.0 - Admin+ Stored Cross Site Scripting
unknown
- Affected:
- up to 3.12.2
- Fixed in:
- 3.12.2
- Disclosed:
- Jul 10, 2024
CVE-2024-6708 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.7 - Missing Authorization to Unauthenticated Media Upload
medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized file uplloads due to a missing capability check on the wppb_upload_file_type() function in all versions up to, and including, 3.11.7. This makes it possible for unauthenticat...
- CVSS:
- 5.3
- Affected:
- up to 3.11.7
- Fixed in:
- 3.11.8
- Disclosed:
- Jul 8, 2024
CVE-2024-6366 on NVD →
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
unknown
- Affected:
- up to 3.11.8
- Fixed in:
- 3.11.8
- Disclosed:
- Jul 8, 2024
CVE-2024-6366 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.11.3
unknown
[en] Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.
- Affected:
- up to 3.11.3
- Fixed in:
- 3.11.3
- Disclosed:
- May 17, 2024
CVE-2024-31341 on NVD →
Profile Builder <= 3.11.2 - Restricted Email Bypass
medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to restricted email domain bypass in all versions up to, and including, 3.11.2. This makes it possible for unauthenticated attackers to register with emails that are restricted.
- CVSS:
- 5.3
- Affected:
- up to 3.11.2
- Fixed in:
- 3.11.3
- Disclosed:
- Apr 5, 2024
CVE-2024-31341 on NVD →
Profile Builder < 3.11.3 - Restricted Email Bypass
unknown
- Affected:
- up to 3.11.3
- Fixed in:
- 3.11.3
- Disclosed:
- Apr 5, 2024
CVE-2024-31341 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.10.9
unknown
[en] The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all versions up to, and including, 3.10.8. Thi...
- Affected:
- up to 3.10.9
- Fixed in:
- 3.10.9
- Disclosed:
- Feb 5, 2024
CVE-2024-0324 on NVD →
User Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update
high
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all versions up to, and including, 3.10.8. This mak...
- CVSS:
- 8.2
- Affected:
- up to 3.10.8
- Fixed in:
- 3.10.9
- Disclosed:
- Jan 16, 2024
CVE-2024-0324 on NVD →
User Profile Builder < 3.10.9 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update
medium
- Affected:
- up to 3.10.9
- Fixed in:
- 3.10.9
- Disclosed:
- Jan 16, 2024
CVE-2024-0324 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.10.8
unknown
[en] The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wppb_toolbox_usermeta_handler function in all versions up to, and including, 3.10.7. This makes it possible for a...
- Affected:
- up to 3.10.8
- Fixed in:
- 3.10.8
- Disclosed:
- Jan 11, 2024
CVE-2023-6504 on NVD →
Profile Builder <= 3.10.7 - Insecure Direct Object Reference to Sensitive Information Exposure via user_meta Shortcode
medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wppb_toolbox_usermeta_handler function in all versions up to, and including, 3.10.7. This makes it possible for authen...
- CVSS:
- 4.3
- Affected:
- up to 3.10.6
- Fixed in:
- 3.10.8
- Disclosed:
- Jan 5, 2024
CVE-2023-6504 on NVD →
Profile Builder < 3.10.8 - Contributor+ User Metadata Disclosure
unknown
- Affected:
- up to 3.10.8
- Fixed in:
- 3.10.8
- Disclosed:
- Jan 5, 2024
CVE-2023-6504 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.10.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin <= 3.10.3 versions.
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.4
- Disclosed:
- Nov 13, 2023
CVE-2023-47669 on NVD →
Profile Builder <= 3.10.3 - Cross-Site Request Forgery via pms-cross-promotion.php
high
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.10.3. This is due to missing or incorrect nonce validation on the wppb_activate_pms_plugin and wppb_deactivate_pms_plugi...
- CVSS:
- 7.1
- Affected:
- up to 3.10.3
- Fixed in:
- 3.10.4
- Disclosed:
- Nov 7, 2023
CVE-2023-47669 on NVD →
Profile Builder < 3.10.4 - Plugins Activation/Deactivation CSRF
medium
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.4
- Disclosed:
- Nov 7, 2023
CVE-2023-47669 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.10.4
unknown
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.10.3. This is due to missing or incorrect nonce validation on the wppb_activate_pms_plugin and wppb_deactivate_pms_plugi...
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.4
- Disclosed:
- Nov 7, 2023
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.9.8
unknown
[en] The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.8
- Disclosed:
- Sep 4, 2023
CVE-2023-4059 on NVD →
Profile Builder < 3.9.8 - Unauthenticated Plugin's Pages Creation
unknown
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.8
- Disclosed:
- Aug 9, 2023
CVE-2023-4059 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.9.8
unknown
Update the WordPress Profile Builder plugin to the latest available version (at least 3.9.8).
WordFence discovered and reported this Broken Access Control vulnerability in WordPress Profile Builder Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function...
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.8
- Disclosed:
- Aug 9, 2023
Profile Builder <= 3.9.7 - Missing Authorization to Initial Page Creation
medium
The Profile Builder plugin for WordPress is vulnerable to unauthorized page creation due to a missing capability check on the wppb_create_form_pages() function called via an admin_init action in versions up to, and including, 3.9.7. This makes it possible for unauthenticated attackers to trigger the initial page creati...
- CVSS:
- 5.3
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.8
- Disclosed:
- Aug 8, 2023
CVE-2023-4059 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.9.8
unknown
The Profile Builder plugin for WordPress is vulnerable to unauthorized page creation due to a missing capability check on the wppb_create_form_pages() function called via an admin_init action in versions up to, and including, 3.9.7. This makes it possible for unauthenticated attackers to trigger the initial page creati...
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.8
- Disclosed:
- Aug 8, 2023
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.9.1
unknown
[en] The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (wppb_front_end_p...
- Affected:
- up to 3.9.1
- Fixed in:
- 3.9.1
- Disclosed:
- Apr 26, 2023
CVE-2023-2297 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.9.1
unknown
[en] The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This...
- Affected:
- up to 3.9.1
- Fixed in:
- 3.9.1
- Disclosed:
- Feb 14, 2023
CVE-2023-0814 on NVD →
Profile Builder – User Profile & User Registration Forms <= 3.9.0 - Insecure Password Reset Mechanism
critical
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (wppb_front_end_passwo...
- CVSS:
- 9.8
- Affected:
- up to 3.9.0
- Fixed in:
- 3.9.1
- Disclosed:
- Feb 13, 2023
CVE-2023-2297 on NVD →
Profile Builder – User Profile & User Registration Forms <= 3.9.0 - Sensitive Information Disclosure via Shortcode
medium
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This make...
- CVSS:
- 6.5
- Affected:
- up to 3.9.0
- Fixed in:
- 3.9.1
- Disclosed:
- Feb 13, 2023
CVE-2023-0814 on NVD →
Profile Builder < 3.9.1 - Subscriber+ Arbitrary User Meta Disclosure
unknown
- Affected:
- up to 3.9.1
- Fixed in:
- 3.9.1
- Disclosed:
- Feb 13, 2023
CVE-2023-0814 on NVD →
Profile Builder < 3.9.1 - Unauthorised Password Reset
unknown
- Affected:
- up to 3.9.1
- Fixed in:
- 3.9.1
- Disclosed:
- Feb 13, 2023
CVE-2023-2297 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.6.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on.
- Affected:
- up to 3.6.5
- Fixed in:
- 3.6.5
- Disclosed:
- Oct 11, 2022
CVE-2021-36915 on NVD →
Profile Builder – User Profile & User Registration Forms <= 3.6.4 - Cross-Site Request Forgery
high
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.4. This is due to missing nonce validation on the wppb_pbie_import() & wppb_pbie_export_our_json() functions. This makes it possible for unauthenticated att...
- CVSS:
- 8.8
- Affected:
- up to 3.6.4
- Fixed in:
- 3.6.5
- Disclosed:
- Sep 29, 2022
CVE-2021-36915 on NVD →
Profile Builder < 3.6.1 - Settings Import via CSRF
medium
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- Sep 29, 2022
CVE-2021-36915 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.6.8
unknown
[en] The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.8
- Disclosed:
- Apr 4, 2022
CVE-2022-0884 on NVD →
Profile Builder <= 3.6.7 - Admin+ Stored Cross-Site Scripting
medium
The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed
- CVSS:
- 5.5
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.8
- Disclosed:
- Mar 9, 2022
CVE-2022-0884 on NVD →
Profile Builder < 3.6.8 - Admin+ Stored Cross-Site Scripting
medium
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.8
- Disclosed:
- Mar 9, 2022
CVE-2022-0884 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.6.2
unknown
[en] The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that exec...
- Affected:
- up to 3.6.2
- Fixed in:
- 3.6.2
- Disclosed:
- Feb 24, 2022
CVE-2022-0653 on NVD →
Profile Builder - User Profile & User Registration Forms <= 3.6.1 - Cross-Site Scripting via site_url Parameter
medium
The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes...
- CVSS:
- 6.1
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.2
- Disclosed:
- Feb 17, 2022
CVE-2022-0653 on NVD →
Profile Builder < 3.6.2 - Reflected Cross-Site Scripting
medium
- Affected:
- up to 3.6.2
- Fixed in:
- 3.6.2
- Disclosed:
- Feb 17, 2022
CVE-2022-0653 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.4.9
unknown
[en] The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for...
- Affected:
- up to 3.4.9
- Fixed in:
- 3.4.9
- Disclosed:
- Aug 16, 2021
CVE-2021-24527 on NVD →
Profile Builder < 3.5.1 - Reflected Cross-Site Scripting
medium
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.1
- Disclosed:
- Aug 10, 2021
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.4.8
unknown
[en] The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored...
- Affected:
- up to 3.4.8
- Fixed in:
- 3.4.8
- Disclosed:
- Aug 2, 2021
CVE-2021-24448 on NVD →
Profile Builder <= 3.4.8 - Admin Access via Password Reset
critical
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for exam...
- CVSS:
- 9.8
- Affected:
- up to 3.4.9
- Fixed in:
- 3.4.9
- Disclosed:
- Jul 19, 2021
CVE-2021-24527 on NVD →
Profile Builder < 3.4.9 - Admin Access via Password Reset
unknown
- Affected:
- up to 3.4.9
- Fixed in:
- 3.4.9
- Disclosed:
- Jul 19, 2021
CVE-2021-24527 on NVD →
Profile Builder <= 3.4.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping on the 'Modify default Redirect Delay timer' setting. This makes it possible for authenticated attackers. with administrator-level priv...
- CVSS:
- 5.5
- Affected:
- up to 3.4.7
- Fixed in:
- 3.4.8
- Disclosed:
- Jun 30, 2021
CVE-2021-24448 on NVD →
Profile Builder < 3.4.8 - Authenticated Stored XSS
medium
- Affected:
- up to 3.4.8
- Fixed in:
- 3.4.8
- Disclosed:
- Jun 30, 2021
CVE-2021-24448 on NVD →
Profile Builder/Profile Builder Pro <= 3.3.2 - Authenticated Blind SQL Injection
high
The Profile Builder/Profile Builder Pro plugins for WordPress is vulnerable to blind SQL Injection via multiple parameters in versions up to, and including, 3.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenti...
- CVSS:
- 8.8
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
- Disclosed:
- Dec 4, 2020
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.3.3
unknown
The Profile Builder/Profile Builder Pro plugins for WordPress is vulnerable to blind SQL Injection via multiple parameters in versions up to, and including, 3.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenti...
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
- Disclosed:
- Dec 4, 2020
Profile Builder & Profile Builder Pro < 3.3.3 - Authenticated Blind SQL Injection
critical
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
- Disclosed:
- Dec 2, 2020
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.3.3
unknown
Authenticated Blind SQL Injection (SQLi) vulnerability found by Lenon Leite in WordPress Profile Builder plugin (versions <= 3.3.2).
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
- Disclosed:
- Dec 2, 2020
Profile Builder <= 3.1.0 - Privilege Escalation
critical
The Profile Builder and Profile Builder Pro plugin versions up to and including 3.1.0 allows unauthenticated attackers to gain administrator-level permissions by registering users on a vulnerable site and assigning their own role.
- CVSS:
- 9.8
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Feb 13, 2020
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.1.1
unknown
The Profile Builder and Profile Builder Pro plugin versions up to and including 3.1.0 allows unauthenticated attackers to gain administrator-level permissions by registering users on a vulnerable site and assigning their own role.
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Feb 13, 2020
Profile Builder and Profile Builder Pro < 3.1.1 - User Registration With Administrator Role
unknown
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Feb 10, 2020
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.1.1
unknown
User Registration With Administrator Role vulnerability found by Noman Riffat in WordPress Profile Builder plugin (versions <= 3.1.0).
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Feb 10, 2020
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 2.1.4
unknown
[en] The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4
- Disclosed:
- Aug 22, 2019
CVE-2015-9337 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 1.1.66
unknown
[en] The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
- Affected:
- up to 1.1.66
- Fixed in:
- 1.1.66
- Disclosed:
- Aug 21, 2019
CVE-2014-10380 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 2.4.2
unknown
[en] The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.2
- Disclosed:
- Aug 21, 2019
CVE-2016-10911 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 2.2.5
unknown
[en] The profile-builder plugin before 2.2.5 for WordPress has XSS.
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Aug 21, 2019
CVE-2015-9328 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 2.0.3
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Oct 6, 2017
CVE-2014-8492 on NVD →
Profile Builder < 2.5.8 - Cross-Site Scripting
medium
The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wppb_general_settings[minimum_password_length]’ parameter in versions before 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with high privileges to inject...
- CVSS:
- 5.5
- Affected:
- up to 2.5.8
- Fixed in:
- 2.5.8
- Disclosed:
- Mar 10, 2017
Profile Builder < 2.5.8 - Authenticated Stored Cross-Site Scripting (XSS)
medium
- Affected:
- up to 2.5.8
- Fixed in:
- 2.5.8
- Disclosed:
- Mar 10, 2017
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 2.5.8
unknown
The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wppb_general_settings[minimum_password_length]’ parameter in versions before 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with high privileges to inject...
- Affected:
- up to 2.5.8
- Fixed in:
- 2.5.8
- Disclosed:
- Mar 10, 2017
Profile Builder – User Profile & User Registration Forms < 2.4.2 - Cross-Site Scripting
medium
The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.
- CVSS:
- 6.1
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.2
- Disclosed:
- Jul 13, 2016
CVE-2016-10911 on NVD →
Profile Builder < 2.4.2 - Reflected Cross-Site Scripting (XSS)
medium
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.2
- Disclosed:
- Jul 13, 2016
CVE-2016-10911 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 2.4.2
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.2
- Disclosed:
- Jul 13, 2016
Profile Builder < 2.4.1 - Privilege Escalation
critical
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Jul 8, 2016
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 2.4.1
unknown
This plugin is prone to a privilege escalation vulnerability.
Update this plugin.
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Jul 8, 2016
Profile Builder <= 2.4.0 - Privilege Escalation
high
The Profile Builder plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.4.0. This makes it possible for subscriber-level attackers to elevate user roles to administrative levels, giving them full control of the website. This vulnerability only impacts websites that have regi...
- CVSS:
- 8.8
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Jul 7, 2016
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 2.4.1
unknown
The Profile Builder plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.4.0. This makes it possible for subscriber-level attackers to elevate user roles to administrative levels, giving them full control of the website. This vulnerability only impacts websites that have regi...
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Jul 7, 2016
Profile Builder – User Profile & User Registration Forms <= 2.2.4 - Reflected Cross-Site Scripting
medium
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'loginerror', 'wckerrorfields', 'wckerrormessages', and 'field_name' parameters in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. Th...
- CVSS:
- 6.1
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Nov 11, 2015
CVE-2015-9328 on NVD →
Profile Builder < 2.2.5 - XSS
medium
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Nov 11, 2015
CVE-2015-9328 on NVD →
Profile Builder <= 2.1.3 - Missing Access Controls
high
The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.
- CVSS:
- 7.5
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.4
- Disclosed:
- Apr 15, 2015
CVE-2015-9337 on NVD →
Profile Builder < 2.1.4 - Missing Access Controls
unknown
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4
- Disclosed:
- Apr 15, 2015
CVE-2015-9337 on NVD →
Profile Builder <= 2.0.2 - Reflected Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.
- CVSS:
- 6.1
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.3
- Disclosed:
- Oct 30, 2014
CVE-2014-8492 on NVD →
Profile Builder < 2.0.3 - Reflected Cross-Site Scripting (XSS)
medium
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Oct 30, 2014
CVE-2014-8492 on NVD →
Profile Builder < 1.1.60 - Password Recovery Bypass
unknown
- Affected:
- up to 1.1.60
- Fixed in:
- 1.1.60
- Disclosed:
- Aug 1, 2014
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 1.1.60
unknown
Because of this vulnerability, an attacker may exploit this issue to reset account passwords for arbitrary users which may aid in further attacks.
Update the plugin.
- Affected:
- up to 1.1.60
- Fixed in:
- 1.1.60
- Disclosed:
- Aug 1, 2014
Profile Builder – User Profile & User Registration Forms < 1.1.66 - Cross-Site Scripting
medium
The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
- CVSS:
- 6.1
- Affected:
- up to 1.1.66
- Fixed in:
- 1.1.66
- Disclosed:
- Jul 16, 2014
CVE-2014-10380 on NVD →
Profile Builder < 1.1.66 - Multiple XSS
medium
- Affected:
- up to 1.1.66
- Fixed in:
- 1.1.66
- Disclosed:
- Jul 16, 2014
CVE-2014-10380 on NVD →
Profile Builder – User Profile & User Registration Forms Plugin < 1.1.60 - Authentication Bypass
critical
The Profile Builder – User Profile & User Registration Forms Plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.1.59. This is due to a failure to restrict access on the password reset form. This makes it possible for unauthenticated attackers to reset passwords of user accou...
- CVSS:
- 9.8
- Affected:
- up to 1.1.60
- Fixed in:
- 1.1.60
- Disclosed:
- May 6, 2014
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 1.1.60
unknown
The Profile Builder – User Profile & User Registration Forms Plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.1.59. This is due to a failure to restrict access on the password reset form. This makes it possible for unauthenticated attackers to reset passwords of user accou...
- Affected:
- up to 1.1.60
- Fixed in:
- 1.1.60
- Disclosed:
- May 6, 2014
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.5.1
unknown
The plugin does not escape some generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.1
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.3.3
unknown
The orderby parameter of the wp-admin/users.php?page=unconfirmed_emails&orderby=email&order=asc page, which is available when the "Email confirmation" setting of the plugin is activated (default is off), is not properly sanitised and validated before being concatenated in a SQL statement, leading to a...
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.1.1
unknown
The plugin is affected by a broken authentication vulnerability, allowing unauthenticated users to register or edit their account and gain the Administrator role using the plugin's forms.
The vulnerability only exists in the Plugin's own generated Registration Form or Profile Edit Form. This means if the b...
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 2.5.8
unknown
Stored Cross-Site Scripting (XSS) in field minimum password length.
- Affected:
- up to 2.5.8
- Fixed in:
- 2.5.8
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 2.4.1
unknown
The User Registration & User Profile – Profile Builder WordPress plugin was affected by a Privilege Escalation security vulnerability.
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 1.1.60
unknown
The User Registration & User Profile – Profile Builder WordPress plugin was affected by a Password Recovery Bypass security vulnerability in the front-end/wppb.recover.password.php file.
- Affected:
- up to 1.1.60
- Fixed in:
- 1.1.60
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.13.7
unknown
- Affected:
- up to 3.13.7
- Fixed in:
- 3.13.7
CVE-2025-2314 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.12.2
unknown
- Affected:
- up to 3.12.2
- Fixed in:
- 3.12.2
CVE-2024-6708 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.13.9
unknown
- Affected:
- up to 3.13.9
- Fixed in:
- 3.13.9
CVE-2025-4671 on NVD →
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.14.4
unknown
- Affected:
- up to 3.14.4
- Fixed in:
- 3.14.4
CVE-2025-8896 on NVD →