The User Profile Builder WordPress plugin before 4.0.1 has a critical vulnerability allowing unauthenticated visitors to upload files and modify content. This issue grants them capabilities typically reserved for privileged roles, enabling them to list the site's media library and modify unpublished posts, pages, and media items belonging to other users. Affected WordPress site administrators and owners s [truncated]
MEDIUMUser Profile BuilderCVE published 2026-08-29
The User Profile Builder WordPress plugin before 4.0.1 has a PHP Object Injection vulnerability when importing configuration files, exploitable by high-privilege users like administrators. This feature is a free add-on, disabled by default, and requires a suitable gadget from another installed plugin for further impact. The vulnerability allows high privilege users such as administrators to conduct PHP Ob [truncated]
MEDIUMUser Profile BuilderCVE published 2026-03-31
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference. This vulnerability allows authenticated attackers with subscriber-level access to reassign post and attachment ownership. The plugin's vulnerability stems from missing validation on a user-controlled key in the wppb_save_avatar_value() funct [truncated]