Extension WordPress
Vulnérabilités User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor, page 2
Cette page rassemble les failles publiées pour User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
33 fiches
Profile Builder – User Profile & User Registration Forms <= 3.6.1 – Cross-Site Scripting via site_url Parameter
The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary…
*-3.6.1
3.6.2
17/02/2022
Profile Builder <= 3.4.8 – Admin Access via Password Reset
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in…
[*, 3.4.9)
3.4.9
19/07/2021
Profile Builder <= 3.4.7 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping on the 'Modify default Redirect Delay timer' setting. This makes it…
*-3.4.7
3.4.8
30/06/2021
Profile Builder/Profile Builder Pro <= 3.3.2 – Authenticated Blind SQL Injection
The Profile Builder/Profile Builder Pro plugins for WordPress is vulnerable to blind SQL Injection via multiple parameters in versions up to, and including, 3.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
[*, 3.3.3)
3.3.3
04/12/2020
Profile Builder <= 3.1.0 – Privilege Escalation
The Profile Builder and Profile Builder Pro plugin versions up to and including 3.1.0 allows unauthenticated attackers to gain administrator-level permissions by registering users on a vulnerable site and assigning their own role.
[*, 3.1.1)
3.1.1
13/02/2020
Profile Builder < 2.5.8 – Cross-Site Scripting
The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wppb_general_settings[minimum_password_length]’ parameter in versions before 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with high privileges…
[*, 2.5.8)
2.5.8
10/03/2017
Profile Builder – User Profile & User Registration Forms < 2.4.2 – Cross-Site Scripting
The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.
[*, 2.4.2)
2.4.2
13/07/2016
Profile Builder <= 2.4.0 – Privilege Escalation
The Profile Builder plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.4.0. This makes it possible for subscriber-level attackers to elevate user roles to administrative levels, giving them full control of the…
[*, 2.4.1)
2.4.1
07/07/2016
Profile Builder – User Profile & User Registration Forms <= 2.2.4 – Reflected Cross-Site Scripting
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'loginerror', 'wckerrorfields', 'wckerrormessages', and 'field_name' parameters in versions up to, and including, 2.2.4 due to insufficient input…
[*, 2.2.5)
2.2.5
11/11/2015
Profile Builder <= 2.1.3 – Missing Access Controls
The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.
*-2.1.3
2.1.4
15/04/2015
Profile Builder <= 2.0.2 – Reflected Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.
*-2.0.2
2.0.3
30/10/2014
Profile Builder – User Profile & User Registration Forms < 1.1.66 – Cross-Site Scripting
The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
[*, 1.1.66)
1.1.66
16/07/2014
Profile Builder – User Profile & User Registration Forms Plugin < 1.1.60 – Authentication Bypass
The Profile Builder – User Profile & User Registration Forms Plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.1.59. This is due to a failure to restrict access on the password reset…
[*, 1.1.60)
1.1.60
06/05/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.