CVE · Critical

CVE-2021-24527 — User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.4.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24527 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.4.9 Improper Authentication Critical 9.8 < 3.4.9 3.4.9 2021-07-19

CVE-2021-24527

The User Registration & User Profile – Profile Builder plugin versions before 3.4.9 contain a flaw in password reset key validation that permits any user to reset the administrator's password without authorization. The plugin fails to properly verify the reset key, enabling attackers to gain admin access while bypassing email notification mechanisms that would normally alert the administrator to the account compromise.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.