VYPR

Profile Builder Pro

by WordPress

CVEs (5)

  • CVE-2024-22140HigJan 31, 2024
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.

  • CVE-2026-7647HigMay 2, 2026
    risk 0.53cvss 8.1epss 0.00

    The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter within the…

  • CVE-2024-22142HigJan 13, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Profile Builder Pro allows Reflected XSS.This issue affects Profile Builder Pro: from n/a through 3.10.0.

  • CVE-2024-22141MedJan 24, 2024
    risk 0.42cvss 6.5epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.

  • CVE-2026-42385Jun 17, 2026
    risk 0.00cvss epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.