Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the vendor User Profile Builder, specifically concerning its product "Beautiful User Registration Forms, User Profiles & User Role Editor," categorized by weakness type and security tags. It collects a comprehensive history of reported flaws, including authentication bypasses, privilege escalation issues, and cross-site scripting vulnerabilities, covering the period from the product's initial release through recent disclosures. Readers can use this resource to track the vendor’s advisory patterns, understand the specific weakness classes prevalent in user management plugins, and review the complete vulnerability history of this WordPress extension. The data provides a factual overview of past security incidents, enabling developers and security professionals to assess the risk profile of this specific software component without relying on fragmented individual reports. This aggregation serves as a centralized reference for analyzing how the product has handled security updates and patching over time, offering insights into recurring themes in its codebase. By consolidating these records, the page facilitates a clearer understanding of the security posture of this user profile management tool, helping stakeholders make informed decisions about its deployment and maintenance. The focus remains strictly on documented security defects and their classifications, providing a neutral view of the product’s historical security performance.

Vendor: cozmoslabs

CVE ID Title CVSS Severity Published
CVE-2026-95866 User Profile Builder <= 4.0.2 - Unauthenticated Stored Cross-Site Scripting via Avatar Field CWE-79 7.2 High 2026-09-25
CVE-2026-93656 User Profile Builder <= 4.0.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Field CWE-79 6.4 Medium 2026-09-25
CVE-2026-6431 User Profile Builder <= 3.15.7 - Unauthenticated Stored Cross-Site Scripting via 'Biographical Info' Meta Field CWE-79 7.2 High 2026-09-07
CVE-2026-75964 User Profile Builder <= 4.0.0 - Unauthenticated Stored Cross-Site Scripting via 'email' Parameter CWE-79 6.1 Medium 2026-09-01
CVE-2026-75965 User Profile Builder <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'date' Shortcode Attribute CWE-79 6.4 Medium 2026-09-01
CVE-2026-15826 User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter CWE-704 9.8 Critical 2026-08-15
CVE-2026-3139 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field CWE-639 4.3 Medium 2026-03-31
CVE-2025-13054 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium 2025-11-19
CVE-2025-8896 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2025-08-16
CVE-2025-4671 Profile Builder <= 3.13.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes CWE-79 6.4 Medium 2025-06-03
CVE-2025-2314 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium 2025-04-16
CVE-2024-12738 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.9 - Unauthenticated Stored Cross-Site Scripting CWE-79 6.1 Medium 2025-01-07
CVE-2024-0324 User Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update CWE-284 8.2 High 2024-02-05
CVE-2023-6504 Profile Builder <= 3.10.7 - Insecure Direct Object Reference to Sensitive Information Exposure via user_meta Shortcode CWE-639 4.3 Medium 2024-01-11
CVE-2023-47669 WordPress Profile Builder Plugin <= 3.10.3 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 5.4 Medium 2023-11-13
CVE-2023-2297 Profile Builder – User Profile & User Registration Forms <= 3.9.0 - Insecure Password Reset Mechanism CWE-620 9.8 Critical 2023-04-26
CVE-2023-0814 Profile Builder – User Profile & User Registration Forms <= 3.9.0 - Sensitive Information Disclosure via Shortcode CWE-200 6.5 Medium 2023-02-14

All 17 known CVE vulnerabilities affecting User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor with full Chinese analysis, references, and POCs where available.