WordPress Plugin Vulnerabilities

Profile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/Export

Description

The plugin does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is present in the plugin itself, so further impact requires a suitable gadget from another installed plugin or theme.

Proof of Concept

Affects Plugins

Fixed in 4.0.1

References

Classification

Type
OBJECT INJECTION
CWE

Miscellaneous

Original Researcher
Vivien LEBAS
Submitter
Vivien LEBAS
Verified
Yes

Timeline

Publicly Published
2026-08-27 (about 2 days ago)
Added
2026-08-27 (about 1 day ago)
Last Updated
2026-08-27 (about 1 day ago)

Other