VYPR

User registration & user profile

by WordPress

CVEs (3)

  • CVE-2021-24527CriAug 16, 2021
    risk 0.64cvss 9.8epss 0.08

    The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not…

  • CVE-2023-0824MedJan 16, 2024
    risk 0.42cvss 6.5epss 0.00

    The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.

  • CVE-2021-24448MedAug 2, 2021
    risk 0.31cvss 4.8epss 0.01

    The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is…