VYPR

Profile Builder

by WordPress

Source repositories

CVEs (38)

  • CVE-2025-15030CriFeb 2, 2026
    risk 0.64cvss 9.8epss 0.01

    The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

  • CVE-2023-2297CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.01

    The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the…

  • CVE-2024-6366CriJul 29, 2024
    risk 0.61cvss 9.1epss 0.29

    The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

  • CVE-2026-15826CriAug 15, 2026
    risk 0.57cvss 9.8epss 0.04

    The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an…

  • CVE-2026-76548HigAug 29, 2026
    risk 0.53cvss 8.2epss 0.00

    The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts,…

  • CVE-2026-15368HigAug 1, 2026
    risk 0.53cvss 8.1epss 0.00

    The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including…

  • CVE-2024-0324HigFeb 5, 2024
    risk 0.53cvss 8.2epss 0.02

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all…

  • CVE-2015-9337HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.01

    The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.

  • CVE-2026-95866HigSep 25, 2026
    risk 0.47cvss 7.2epss 0.00

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output…

  • CVE-2026-82607HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in…

  • CVE-2026-76546MedAug 29, 2026
    risk 0.44cvss 6.8epss 0.00

    The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including…

  • CVE-2026-76547MedAug 29, 2026
    risk 0.43cvss 6.6epss 0.00

    The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is…

  • CVE-2026-96338MedSep 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.

  • CVE-2025-8896MedAug 16, 2025
    risk 0.42cvss 6.4epss 0.00

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_communication_preferences[]' parameter in all versions up to, and including, 3.14.3 due to…

  • CVE-2023-0814MedFeb 14, 2023
    risk 0.42cvss 6.5epss 0.01

    The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restriction on sensitive user meta values that…

  • CVE-2026-6431HigSep 7, 2026
    risk 0.40cvss 7.2epss 0.00

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient…

  • CVE-2022-0653MedFeb 24, 2022
    risk 0.40cvss 6.1epss 0.03

    The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject…

  • CVE-2016-10911MedAug 21, 2019
    risk 0.40cvss 6.1epss 0.01

    The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.

  • CVE-2015-9328MedAug 21, 2019
    risk 0.40cvss 6.1epss 0.01

    The profile-builder plugin before 2.2.5 for WordPress has XSS.

  • CVE-2014-10380MedAug 21, 2019
    risk 0.40cvss 6.1epss 0.01

    The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.

Page 1 of 2

VYPR — Vulnerability Intelligence