PT-2026-83404 · WordPress · User Profile Builder
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
User Profile Builder versions prior to 4.0.1
Description
The User Profile Builder WordPress plugin fails to properly restrict its front-end file upload feature. This flaw allows unauthenticated visitors to obtain privileges reserved for privileged roles, enabling them to list the site media library and modify unpublished posts, pages, and media items belonging to other users.
Recommendations
Update the User Profile Builder plugin to version 4.0.1 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
User Profile Builder