📦 Profile Builder

by Cozmoslabs

🔍 What is Profile Builder?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-6695

CRITICAL CVSS 9.8 Jul 31, 2024

This vulnerability allows unauthenticated attackers to gain administrative access to affected systems by exploiting a logic flaw in the user registration process. Attackers can perform any administrat...

CVE-2024-6366

CRITICAL CVSS 9.1 Jul 29, 2024

The User Profile Builder WordPress plugin before version 3.11.8 has an authorization vulnerability that allows unauthenticated users to upload media files via the async upload functionality. This affe...

CVE-2023-2297

CRITICAL CVSS 9.8 Apr 27, 2023

The Profile Builder WordPress plugin up to version 3.9.0 uses plaintext password reset keys instead of hashed values, allowing attackers to reset user passwords without authorization. This vulnerabili...

CVE-2021-24527

CRITICAL CVSS 9.8 Aug 16, 2021

This vulnerability in the Profile Builder WordPress plugin allows any user to reset the administrator password without proper authorization, potentially gaining full control of the WordPress site. The...

CVE-2024-22140

HIGH CVSS 8.8 Jan 31, 2024

This CSRF vulnerability in Profile Builder Pro WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions. Successful exploitation could lead to account...

CVE-2024-22142

HIGH CVSS 7.1 Jan 13, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by Profile Builder Pro, a WordPress plugin. When users visit a specially crafted URL, the scripts execute in th...

CVE-2024-6708

MEDIUM CVSS 4.8 May 15, 2025

This vulnerability in the User Profile Builder WordPress plugin allows authenticated administrators to inject malicious scripts into admin pages. It affects WordPress sites using User Profile Builder ...