The Profile Builder plugin before 3.4.9 for WordPress allows unauthenticated attackers to gain administrative access by exploiting an improper authentication vulnerability in the password reset functionality. An attacker can reset the password of any user, including administrators, without proper authorization, leading to a complete site compromise.
id: CVE-2021-24527
info:
name: Profile Builder < 3.4.9 - Improper Authentication
author: Sourab
...