plugin

Profile Builder Pro Vulnerabilities

8 known security issues reported for the Profile Builder Pro WordPress plugin. Most recent disclosed May 1, 2026.

1 critical 5 high 2 medium

Running Profile Builder Pro on your site? Check whether your installed version is affected.

Scan your site free

Profile Builder Pro <= 3.14.5 - Unauthenticated PHP Object Injection

high

The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter within the wppb_request_users_pins_action_callback() AJAX handler, which lacked any...

CVSS:
8.1
Affected:
up to 3.14.5
Fixed in:
3.14.6
Disclosed:
May 1, 2026

CVE-2026-7647 on NVD →

Profile Builder Pro <= 3.15.0 - Unauthenticated Stored Cross-Site Scripting

high

The Profile Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.15.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user a...

CVSS:
7.2
Affected:
up to 3.15.0
Fixed in:
3.15.1
Disclosed:
Apr 27, 2026

CVE-2026-42385 on NVD →

Profile Builder Pro < 3.14.0 - Unauthenticated SQL Injection

high

The Profile Builder Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 3.14.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL que...

CVSS:
7.5
Affected:
up to 3.14.0
Fixed in:
3.14.0
Disclosed:
Feb 23, 2026

CVE-2026-27413 on NVD →

Profile Builder Pro <= 3.10.0 - Cross-Site Request Forgery

high

The Profile Builder Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.10.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site...

CVSS:
8.8
Affected:
up to 3.10.0
Fixed in:
3.10.1
Disclosed:
Jan 10, 2024

CVE-2024-22140 on NVD →

Profile Builder Pro <= 3.10.0 - Authenticated (Subscriber+) Time-Based One-Time Password Sensitive Information Exposure

medium

The Profile Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.10.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract a sensitive time-based one-time password (TOTP).

CVSS:
6.5
Affected:
up to 3.10.0
Fixed in:
3.10.1
Disclosed:
Jan 10, 2024

CVE-2024-22141 on NVD →

Profile Builder Pro <= 3.10.0 - Reflected Cross-Site Scripting

medium

The Profile Builder Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...

CVSS:
6.1
Affected:
up to 3.10.0
Fixed in:
3.10.1
Disclosed:
Jan 10, 2024

CVE-2024-22142 on NVD →

Profile Builder/Profile Builder Pro <= 3.3.2 - Authenticated Blind SQL Injection

high

The Profile Builder/Profile Builder Pro plugins for WordPress is vulnerable to blind SQL Injection via multiple parameters in versions up to, and including, 3.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenti...

CVSS:
8.8
Affected:
up to 3.3.3
Fixed in:
3.3.3
Disclosed:
Dec 4, 2020

Profile Builder <= 3.1.0 - Privilege Escalation

critical

The Profile Builder and Profile Builder Pro plugin versions up to and including 3.1.0 allows unauthenticated attackers to gain administrator-level permissions by registering users on a vulnerable site and assigning their own role.

CVSS:
9.8
Affected:
up to 3.1.1
Fixed in:
3.1.1
Disclosed:
Feb 13, 2020

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database