Profile Builder <= 3.4.8 - Admin Access via Password Reset
2021-07-19 00:00
StiofanStrategic Overview
StatusPatched in 3.4.9
Affected PluginUser Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
Affected Version
< 3.4.9CVSS9.8Critical
CVE
CVE-2021-24527Vulnerability Overview
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.
Technical Analysis
REMEDIATION: Update to version 3.4.9, or a newer patched version --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C