PatchSiren cyber security CVE debrief
CVE-2026-3139 User Profile Builder CVE debrief
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference. This vulnerability allows authenticated attackers with subscriber-level access to reassign post and attachment ownership. The plugin's vulnerability stems from missing validation on a user-controlled key in the wppb_save_avatar_value() function, enabling attackers to change 'post_author' and gain unauthorized control over posts and attachments. This issue affects versions up to and including 3.15.5 of the plugin. The CVSS score of 4.3 indicates a Medium severity level, emphasizing the need for prompt action to protect sites using this plugin. Users of the User Profile Builder plugin, particularly those with subscriber-level access, should be aware of this vulnerability and take steps to protect their sites by updating the plugin to the latest version, restricting access to sensitive functions for subscribers and lower-privileged users, and monitoring site activity for suspicious post and attachment changes.
- Vendor
- User Profile Builder
- Product
- User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-31
- Original CVE updated
- 2026-07-25
- Advisory published
- 2026-03-31
- Advisory updated
- 2026-07-25
Who should care
Users of the User Profile Builder plugin, particularly those with subscriber-level access, should be aware of this vulnerability and take steps to protect their sites. Site administrators, security teams, and operators using the User Profile Builder plugin should review their deployments, assess the potential impact, and implement necessary mitigations. This includes updating the plugin to the latest version, restricting access to sensitive functions, and monitoring site activity for suspicious changes.
Technical summary
The User Profile Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing validation on a user-controlled key in the wppb_save_avatar_value() function. This allows authenticated attackers with subscriber-level access to reassign ownership of arbitrary posts and attachments by changing 'post_author'. The vulnerability affects versions up to and including 3.15.5 of the plugin. The CVSS score for this vulnerability is 4.3, indicating a Medium severity level. To mitigate this vulnerability, users should update the User Profile Builder plugin to the latest version, restrict access to sensitive functions for subscribers and lower-privileged users, and monitor site activity for suspicious post and attachment changes.
Defensive priority
Medium priority due to the CVSS score of 4.3 and the potential impact on site security.
Recommended defensive actions
- Update the User Profile Builder plugin to the latest version
- Restrict access to sensitive functions for subscribers and lower-privileged users
- Monitor site activity for suspicious post and attachment changes
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-03-31T12:16:31.037Z and last modified on 2026-07-25T10:10:00.167Z. The NVD entry is currently Deferred. This vulnerability affects the User Profile Builder plugin for WordPress, specifically versions up to and including 3.15.5. The plugin is vulnerable to Insecure Direct Object Reference due to missing validation on a user-controlled key in the wppb_save_avatar_value() function. Authenticated attackers with subscriber-level access and above can exploit this vulnerability to reassign ownership of arbitrary posts and attachments by changing 'post_author'. The CVSS score for this vulnerability is 4.3, indicating a Medium severity level. Users of the User Profile Builder plugin, particularly those with subscriber-level access, should be aware of this vulnerability and take steps to protect their sites. To verify the vulnerability, defenders should check for affected product deployments in managed environments and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-31T12:16:31.037Z and has not been modified since then. The NVD entry is currently Deferred.