Profile Builder Pro <= 3.14.5 - Unauthenticated PHP Object Injection
high
The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter within the wppb_request_users_pins_action_callback() AJAX handler, which lacked any...
- CVSS:
- 8.1
- Affected:
- up to 3.14.5
- Fixed in:
- 3.14.6
- Disclosed:
- May 1, 2026
CVE-2026-7647 on NVD →
Profile Builder Pro <= 3.15.0 - Unauthenticated Stored Cross-Site Scripting
high
The Profile Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.15.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user a...
- CVSS:
- 7.2
- Affected:
- up to 3.15.0
- Fixed in:
- 3.15.1
- Disclosed:
- Apr 27, 2026
CVE-2026-42385 on NVD →
Profile Builder Pro < 3.14.0 - Unauthenticated SQL Injection
high
The Profile Builder Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 3.14.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL que...
- CVSS:
- 7.5
- Affected:
- up to 3.14.0
- Fixed in:
- 3.14.0
- Disclosed:
- Feb 23, 2026
CVE-2026-27413 on NVD →
Profile Builder Pro <= 3.10.0 - Cross-Site Request Forgery
high
The Profile Builder Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.10.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site...
- CVSS:
- 8.8
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.1
- Disclosed:
- Jan 10, 2024
CVE-2024-22140 on NVD →
Profile Builder Pro <= 3.10.0 - Authenticated (Subscriber+) Time-Based One-Time Password Sensitive Information Exposure
medium
The Profile Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.10.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract a sensitive time-based one-time password (TOTP).
- CVSS:
- 6.5
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.1
- Disclosed:
- Jan 10, 2024
CVE-2024-22141 on NVD →
Profile Builder Pro <= 3.10.0 - Reflected Cross-Site Scripting
medium
The Profile Builder Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...
- CVSS:
- 6.1
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.1
- Disclosed:
- Jan 10, 2024
CVE-2024-22142 on NVD →
Profile Builder/Profile Builder Pro <= 3.3.2 - Authenticated Blind SQL Injection
high
The Profile Builder/Profile Builder Pro plugins for WordPress is vulnerable to blind SQL Injection via multiple parameters in versions up to, and including, 3.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenti...
- CVSS:
- 8.8
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.3
- Disclosed:
- Dec 4, 2020
Profile Builder <= 3.1.0 - Privilege Escalation
critical
The Profile Builder and Profile Builder Pro plugin versions up to and including 3.1.0 allows unauthenticated attackers to gain administrator-level permissions by registering users on a vulnerable site and assigning their own role.
- CVSS:
- 9.8
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Feb 13, 2020
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database