CVE-2023-4059Cross-Site Request Forgery in Profile Builder

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 71.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 4

Description

The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-8xqw-5jx9-crgq: The Profile Builder WordPress plugin before 32023-09-04
CVEList
Profile Builder < 3.9.8 - Unauthenticated Plugin's Pages Creation2023-09-04
CVE-2023-4059 — Cross-Site Request Forgery | cvebase