WF-c62d8146-e4b1-4c86-9d8a-c3a9bbfb0763-profile-builder
Profile Builder – User Profile & User Registration Forms Plugin < 1.1.60 - Authentication Bypass
criticalImproper Authentication
9.8
CVSS Score
9.8
CVSS Score
critical
Severity
1.1.60
Patched in
3549d
Time to patch
Description
The Profile Builder – User Profile & User Registration Forms Plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.1.59. This is due to a failure to restrict access on the password reset form. This makes it possible for unauthenticated attackers to reset passwords of user accounts, including administrator accounts.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAttack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
High
Confidentiality
High
Integrity
High
Availability
Technical Details
Affected versions
<1.1.60PublishedMay 6, 2014
Last updatedJanuary 22, 2024
Affected pluginprofile-builder
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.