PatchSiren

User Profile Builder CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM User Profile Builder CVE published 2026-03-31

CVE-2026-3139

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference. This vulnerability allows authenticated attackers with subscriber-level access to reassign post and attachment ownership. The plugin's vulnerability stems from missing validation on a user-controlled key in the wppb_save_avatar_value() funct [truncated]