VulnerabilityModified
CVE-2023-4059
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog
MEDIUM 4.3EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352, CWE-862
- Affected
- cozmoslabs/profile builder
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/fc719d12-2f58-4d1f-b696-0f937e706842Third Party Advisory
- https://wpscan.com/vulnerability/fc719d12-2f58-4d1f-b696-0f937e706842Third Party Advisory
- https://wpscan.com/vulnerability/fc719d12-2f58-4d1f-b696-0f937e706842Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.