Profile Builder <= 2.1.3 - Missing Access Controls
2015-04-15 00:00
AnonymousStrategic Overview
StatusPatched in 2.1.4
Affected PluginUser Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
Affected Version
<= 2.1.3CVSS7.5High
CVE
CVE-2015-9337Vulnerability Overview
The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.
Technical Analysis
REMEDIATION: Update to version 2.1.4, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C