Profile Builder <= 3.13.8 - Unauthenticated Content Spoofing

Vulnerability Overview

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Content Spoofing in all versions up to, and including, 3.13.8. This makes it possible for unauthenticated attackers to spoof content.

Technical Analysis

REMEDIATION: Update to version 3.13.9, or a newer patched version --- IDENTIFIER: CWE-1284 (Improper Validation of Specified Quantity in Input) The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C