WordPress Plugin Vulnerabilities

Profile Builder < 3.9.8 - Unauthenticated Plugin's Pages Creation

Description

The plugin lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog

Proof of Concept

Affects Plugins

Fixed in 3.9.8

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Mesh3l_911
Submitter
Mesh3l_911
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2023-08-09 (about 2 years ago)
Added
2023-08-09 (about 2 years ago)
Last Updated
2023-08-09 (about 2 years ago)

Other