cbcvebase.

Cozmoslabs Profile Builder Pro vulnerabilities

6 known vulnerabilities affecting cozmoslabs/profile_builder_pro.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-27413P2CRITICALCVSS 9.3≥ n/a, < 3.14.02026-03-19
CVE-2026-27413 [CRITICAL] CWE-89 CVE-2026-27413: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14.0.
nvd
CVE-2026-7647P3HIGHCVSS 8.1≤ 3.14.52026-05-02
CVE-2026-7647 [HIGH] CWE-502 CVE-2026-7647: The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions u The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter within the wppb_request_users_pins_action_callback() AJAX handler, which lacked any nonce verification, type checking,
nvd
CVE-2024-22141P3HIGHCVSS 7.5≥ n/a, ≤ 3.10.02024-01-24
CVE-2024-22141 [HIGH] CWE-200 CVE-2024-22141: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Build Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.
nvd
CVE-2024-22140P3HIGHCVSS 8.8≥ n/a, ≤ 3.10.02024-01-31
CVE-2024-22140 [HIGH] CWE-352 CVE-2024-22140: Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.
nvd
CVE-2024-22142P4MEDIUMCVSS 6.1≥ n/a, ≤ 3.10.02024-01-13
CVE-2024-22142 [MEDIUM] CWE-79 CVE-2024-22142: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Profile Builder Pro allows Reflected XSS.This issue affects Profile Builder Pro: from n/a through 3.10.0.
nvd
CVE-2026-42385HIGHCVSS 7.1≥ n/a, ≤ 3.15.02026-06-17
CVE-2026-42385 [HIGH] CWE-79 WordPress Profile Builder Pro plugin <= 3.15.0 - Cross Site Scripting (XSS) vulnerability WordPress Profile Builder Pro plugin <= 3.15.0 - Cross Site Scripting (XSS) vulnerability Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.
cvelistv5
Cozmoslabs Profile Builder Pro vulnerabilities | cvebase