plugin

Ultimate Profile Builder Vulnerabilities

1 known security issue reported for the Ultimate Profile Builder WordPress plugin. Most recent disclosed May 7, 2015.

1 high

Running Ultimate Profile Builder on your site? Check whether your installed version is affected.

Scan your site free

Ultimate Profile Builder < 3.0 - Cross-Site Request Forgery to Cross-Site Scripting

high

The Ultimate Profile Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting via multiple parameters in versions before 3.0 due to insufficient input sanitization and output escaping and missing nonce validation. This makes it possible for unauthenticated attackers to inject ar...

CVSS:
7.1
Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
May 7, 2015

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database