CVE Database /
CVE-2023-0814
CVE · Medium
CVE-2023-0814 — User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.9.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-0814
|
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.9.1 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
6.5
|
< 3.9.1
|
3.9.1 |
2023-02-13 |
—
|
CVE-2023-0814
The Profile Builder plugin for WordPress through version 3.9.0 contains a flaw in the [user_meta] shortcode that fails to properly restrict access to sensitive user metadata, allowing authenticated users with subscriber-level access or higher to retrieve confidential user information that could facilitate unauthorized access to privileged accounts. Exploitation requires that the Usermeta shortcode feature be active on the site. The vulnerability was resolved in version 3.9.1.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings