CVE · Medium

CVE-2023-0814 — User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0814 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.9.1 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 3.9.1 3.9.1 2023-02-13

CVE-2023-0814

The Profile Builder plugin for WordPress through version 3.9.0 contains a flaw in the [user_meta] shortcode that fails to properly restrict access to sensitive user metadata, allowing authenticated users with subscriber-level access or higher to retrieve confidential user information that could facilitate unauthorized access to privileged accounts. Exploitation requires that the Usermeta shortcode feature be active on the site. The vulnerability was resolved in version 3.9.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.