User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
Minimum safe version
3.15.6
Update to 3.15.6 or later to address 47 fixable vulnerabilities
CVE-2025-15030
CVE-2025-13054
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting
CVE-2025-49292
Profile Builder <= 3.13.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.1 - Authenticated (Admin+) Stored Cross-Site Scripting
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
CVE-2024-12738
CVE-2024-6366
CVE-2024-6695
CVE-2024-31341
CVE-2024-0324
CVE-2023-6504
CVE-2023-47669
Profile Builder <= 3.10.3 - Cross-Site Request Forgery via pms-cross-promotion.php
CVE-2023-4059
WordPress Profile Builder Plugin < 3.9.8 is vulnerable to Broken Access Control
Profile Builder <= 3.9.7 - Missing Authorization to Initial Page Creation
Profile Builder < 1.1.60 - Password Recovery Bypass
Profile Builder < 2.4.1 - Privilege Escalation
Profile Builder < 2.5.8 - Authenticated Stored Cross-Site Scripting (XSS)
Profile Builder and Profile Builder Pro < 3.1.1 - User Registration With Administrator Role
Profile Builder & Profile Builder Pro < 3.3.3 - Authenticated Blind SQL Injection
Profile Builder < 3.5.1 - Reflected Cross-Site Scripting
WordPress Profile Builder Plugin <= 3.9.0 is vulnerable to Sensitive Data Exposure
CVE-2023-0814
Profile Builder – User Profile & User Registration Forms Plugin < 1.1.60 - Authentication Bypass
Profile Builder <= 2.4.0 - Privilege Escalation
Profile Builder < 2.5.8 - Cross-Site Scripting
Profile Builder <= 3.1.0 - Privilege Escalation
Profile Builder/Profile Builder Pro <= 3.3.2 - Authenticated Blind SQL Injection
CVE-2021-36915
WordPress Profile Builder Plugin <= 1.1.59 - BYPASS
WordPress Profile Builder Plugin <= 2.4.0 - Privilege Escalation
WordPress Profile Builder Plugin <= 2.4.1 - Reflected Cross Site Scripting
WordPress Profile Builder plugin <= 3.1.0 - User Registration With Administrator Role vulnerability
WordPress Profile Builder plugin <= 3.3.2 - Authenticated Blind SQL Injection (SQLi) vulnerability
CVE-2022-0884
CVE-2014-8492
CVE-2015-9328
CVE-2016-10911
CVE-2014-10380
CVE-2015-9337
CVE-2021-24448
CVE-2021-24527
CVE-2022-0653