User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor

Information

Software Type Plugin
Software Slug profile-builder (view on wordpress.org)
Software Status Active
Software Author cozmoslabs
Software Website www.cozmoslabs.com
Software Downloads 5,599,138
Software Active Installs 40,000
Software Record Last Updated July 16, 2026

Showing 1-20 of 33 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field Patched CVE-2026-3139 4.3 type5afe March 30, 2026
User Profile Builder <= 3.15.1 - Unauthenticated Privilege Escalation via Account Takeover Patched CVE-2025-15030 9.8 Drew Webber (mcdruid) January 12, 2026
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Patched CVE-2025-13054 6.4 Muhammad Yudha - DJ November 18, 2025
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting Patched CVE-2025-8896 6.4 Alex August 15, 2025
Profile Builder <= 3.13.8 - Unauthenticated Content Spoofing Patched CVE-2025-49292 5.3 Trương Hữu Phúc (truonghuuphuc) June 5, 2025
Profile Builder <= 3.13.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes Patched CVE-2025-4671 6.4 Muhammad Yudha - DJ June 2, 2025
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Patched CVE-2025-2314 6.4 Muhammad Yudha - DJ April 15, 2025
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.9 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2024-12738 6.1 Brian Mungai January 6, 2025
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.1 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2024-6708 4.4 John Castro August 13, 2024
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.8 - Authentication Bypass Patched CVE-2024-6695 9.8 John Castro July 10, 2024
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.7 - Missing Authorization to Unauthenticated Media Upload Patched CVE-2024-6366 5.3 Michel Prunet July 8, 2024
Profile Builder <= 3.11.2 - Restricted Email Bypass Patched CVE-2024-31341 5.3 Ananda Dhakal April 5, 2024
User Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update Patched CVE-2024-0324 8.2 kodaichodai January 16, 2024
Profile Builder <= 3.10.7 - Insecure Direct Object Reference to Sensitive Information Exposure via user_meta Shortcode Patched CVE-2023-6504 4.3 Francesco Carlucci January 5, 2024
Profile Builder <= 3.10.3 - Cross-Site Request Forgery via pms-cross-promotion.php Patched CVE-2023-47669 7.1 Brandon James Roldan (tomorrowisnew) November 7, 2023
Profile Builder <= 3.9.7 - Missing Authorization to Initial Page Creation Patched CVE-2023-4059 5.3 Mesh3l_911 August 8, 2023
Profile Builder – User Profile & User Registration Forms <= 3.9.0 - Insecure Password Reset Mechanism Patched CVE-2023-2297 9.8 István Márton February 13, 2023
Profile Builder – User Profile & User Registration Forms <= 3.9.0 - Sensitive Information Disclosure via Shortcode Patched CVE-2023-0814 6.5 István Márton February 13, 2023
Profile Builder – User Profile & User Registration Forms <= 3.6.4 - Cross-Site Request Forgery Patched CVE-2021-36915 8.8 mirphak September 29, 2022
Profile Builder <= 3.6.7 - Admin+ Stored Cross-Site Scripting Patched CVE-2022-0884 5.5 Abhinav Porwal March 9, 2022

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation