WordPress Plugin Vulnerabilities
Profile Builder < 3.9.8 - Unauthenticated Plugin's Pages Creation
Description
The plugin lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Mesh3l_911
Submitter
Mesh3l_911
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2023-08-09 (about 2 years ago)
Added
2023-08-09 (about 2 years ago)
Last Updated
2023-08-09 (about 2 years ago)