VYPR

Profile Builder

by WordPress

Source repositories

CVEs (35)

  • CVE-2025-13054MedNov 19, 2025
    risk 0.35cvss 6.4epss 0.00

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input…

  • CVE-2025-4671MedJun 3, 2025
    risk 0.35cvss 6.4epss 0.00

    The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

  • CVE-2025-2314MedApr 16, 2025
    risk 0.35cvss 6.4epss 0.00

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13.5 due to insufficient input sanitization and…

  • CVE-2023-47669MedNov 13, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin <= 3.10.3 versions.

  • CVE-2026-66701MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.

  • CVE-2024-31341MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.

  • CVE-2026-75964MedSep 1, 2026
    risk 0.33cvss 6.1epss 0.00

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and…

  • CVE-2024-12738MedJan 7, 2025
    risk 0.33cvss 6.1epss 0.00

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user meta parameters in all versions up to, and including, 3.12.9 due to insufficient input sanitization…

  • CVE-2024-6708MedMay 15, 2025
    risk 0.31cvss 4.8epss 0.00

    The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.

  • CVE-2022-0884MedApr 4, 2022
    risk 0.31cvss 4.8epss 0.01

    The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed

  • CVE-2025-49292MedJun 6, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder profile-builder allows Phishing.This issue affects Profile Builder: from n/a through <= 3.13.8.

  • CVE-2023-4059MedSep 4, 2023
    risk 0.28cvss 4.3epss 0.00

    The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog

  • CVE-2021-36915MedOct 11, 2022
    risk 0.27cvss 4.2epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on.

  • CVE-2026-3139MedMar 31, 2026
    risk 0.21cvss 4.3epss 0.00

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value() function due to missing validation on…

  • CVE-2023-6504MedJan 11, 2024
    risk 0.21cvss 4.3epss 0.00

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wppb_toolbox_usermeta_handler function in all versions up to, and…

Page 2 of 2