Profile Builder – User Profile & User Registration Forms Plugin < 1.1.60 - Authentication Bypass
2014-05-06 00:00
AnonymousStrategic Overview
StatusPatched in 1.1.60
Affected PluginUser Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
Affected Version
< 1.1.60CVSS9.8Critical
CVE
N/AVulnerability Overview
The Profile Builder – User Profile & User Registration Forms Plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.1.59. This is due to a failure to restrict access on the password reset form. This makes it possible for unauthenticated attackers to reset passwords of user accounts, including administrator accounts.
Technical Analysis
REMEDIATION: Update to version 1.1.60, or a newer patched version --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C