Profile Builder <= 3.13.8 - Unauthenticated Content Spoofing
2025-06-05 00:00
Trương Hữu Phúc (truonghuuphuc)Strategic Overview
StatusPatched in 3.13.9
Affected PluginUser Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
Affected Version
<= 3.13.8CVSS5.3Medium
CVE
CVE-2025-49292Vulnerability Overview
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Content Spoofing in all versions up to, and including, 3.13.8. This makes it possible for unauthenticated attackers to spoof content.
Technical Analysis
REMEDIATION: Update to version 3.13.9, or a newer patched version --- IDENTIFIER: CWE-1284 (Improper Validation of Specified Quantity in Input) The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C