Unknown User Profile Builder vulnerabilities
4 known vulnerabilities affecting unknown/user_profile_builder.
Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-15030CRITICALCVSS 9.8≥ 1.1.27, < 3.15.22026-02-02
CVE-2025-15030 [CRITICAL] CWE-269 CVE-2025-15030: The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset proce
The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account
cvelistv5nvd
CVE-2024-6708MEDIUMCVSS 4.8fixed in 3.12.22025-05-15
CVE-2024-6708 [MEDIUM] CWE-79 CVE-2024-6708: The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameter
The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.
cvelistv5nvd
CVE-2024-6695CRITICALCVSS 9.8fixed in 3.11.92024-07-31
CVE-2024-6695 [CRITICAL] CWE-863 CVE-2024-6695: it's possible for an attacker to gain administrative access without having any kind of account on th
it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.
cvelistv5nvd
CVE-2024-6366CRITICALCVSS 9.1PoCfixed in 3.11.82024-07-29
CVE-2024-6366 [CRITICAL] CWE-434 CVE-2024-6366: The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowin
The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.
cvelistv5nvd