Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesUser Profile Builder

User Profile Builder vulnerabilities

User Profile Builder has 33 known vulnerabilities in this database. The most recent published record is dated 25 Sep 2026.

Known vulnerabilities
33
Active installs
40,000+
Latest version
4.0.3
Last updated
23 Sep 2026
Most recent
25 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-95866
High 7.2Up to 4.0.2Fixed in a later version (latest 4.0.3)12 d ago
Cross-site scripting (XSS)
CVE-2026-93656
Medium 6.4Up to 4.0.2Fixed in a later version (latest 4.0.3)12 d ago
Cross-site scripting (XSS)
CVE-2026-6431
High 7.2Up to 3.15.7Fixed in a later version (latest 4.0.3)7 Sep 2026
Cross-site scripting (XSS)
CVE-2026-75964
Medium 6.1Up to 4.0.0Fixed in a later version (latest 4.0.3)1 Sep 2026
Cross-site scripting (XSS)
CVE-2026-75965
Medium 6.4Up to 4.0.0Fixed in a later version (latest 4.0.3)1 Sep 2026
PHP object injection
CVE-2026-76547
Medium 6.6Before 4.0.1Fixed in 4.0.129 Aug 2026
Authentication bypass
CVE-2026-76548
High 8.2Before 4.0.1Fixed in 4.0.129 Aug 2026
Cross-site scripting (XSS)
CVE-2026-76546
Medium 6.8Before 4.0.1Fixed in 4.0.129 Aug 2026
Authentication bypass
CVE-2026-15826
Critical 9.8Up to 3.16.4Fixed in a later version (latest 4.0.3)15 Aug 2026
Privilege escalation
CVE-2026-15368
High 8.1Before 3.16.4Fixed in 3.16.41 Aug 2026
Broken access control
CVE-2026-3139
Medium 4.3Up to 3.15.5Fixed in a later version (latest 4.0.3)31 Mar 2026
Privilege escalation
CVE-2025-15030
Critical 9.8Before 3.15.2Fixed in 3.15.22 Feb 2026
Cross-site scripting (XSS)
CVE-2025-13054
Medium 6.4Up to 3.14.8Fixed in a later version (latest 4.0.3)19 Nov 2025
Cross-site scripting (XSS)
CVE-2025-8896
Medium 6.4Up to 3.14.3Fixed in a later version (latest 4.0.3)16 Aug 2025
Cross-site scripting (XSS)
CVE-2025-4671
Medium 6.4Up to 3.13.8Fixed in a later version (latest 4.0.3)3 Jun 2025
Cross-site scripting (XSS)
CVE-2024-6708
Medium 4.8Before 3.12.2Fixed in 3.12.215 May 2025
Cross-site scripting (XSS)
CVE-2025-2314
Medium 6.4Up to 3.13.5Fixed in a later version (latest 4.0.3)16 Apr 2025
Cross-site scripting (XSS)
CVE-2024-12738
Medium 6.1Up to 3.12.9Fixed in a later version (latest 4.0.3)7 Jan 2025
Arbitrary file upload
CVE-2024-6366
Critical 9.1Before 3.11.8Fixed in 3.11.829 Jul 2024
Broken access control
CVE-2024-0324
High 8.2Up to 3.10.8Fixed in a later version (latest 4.0.3)5 Feb 2024
Broken access control
CVE-2023-6504
Medium 4.3Up to 3.10.7Fixed in a later version (latest 4.0.3)11 Jan 2024
Cross-site request forgery (CSRF)
CVE-2023-4059
Medium 4.3Before 3.9.8Fixed in 3.9.84 Sep 2023
SQL injection
CVE-2023-2297
Critical 9.8Up to 3.9.0Fixed in a later version (latest 4.0.3)27 Apr 2023
Sensitive data exposure
CVE-2023-0814
Medium 6.5Up to 3.9.0Fixed in a later version (latest 4.0.3)14 Feb 2023
Cross-site request forgery (CSRF)
CVE-2021-36915
Medium 4.2Up to 3.6.0Fixed in a later version (latest 4.0.3)11 Oct 2022
Cross-site scripting (XSS)
CVE-2022-0884
Medium 4.8Before 3.6.8Fixed in 3.6.84 Apr 2022
Cross-site scripting (XSS)
CVE-2022-0653
Medium 6.1Up to 3.6.1Fixed in a later version (latest 4.0.3)24 Feb 2022
Broken access control
CVE-2021-24527
Critical 9.8Before 3.4.9Fixed in 3.4.916 Aug 2021
Cross-site scripting (XSS)
CVE-2021-24448
Medium 4.8Before 3.4.8Fixed in 3.4.82 Aug 2021
Broken access control
CVE-2015-9337
High 7.5Before 2.1.4Fixed in 2.1.422 Aug 2019
Cross-site scripting (XSS)
CVE-2014-10380
Medium 6.1Before 1.1.66Fixed in 1.1.6621 Aug 2019
Cross-site scripting (XSS)
CVE-2015-9328
Medium 6.1Before 2.2.5Fixed in 2.2.521 Aug 2019
Cross-site scripting (XSS)
CVE-2016-10911
Medium 6.1Before 2.4.2Fixed in 2.4.221 Aug 2019
Read the published descriptions
CVE-2026-95866, 25 Sep 2026
The User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The zero-length multipart file branch in wppb_save_avatar_value() writes the raw request value directly to user meta, bypassing the wppb_save_attachment_id()/wppb_verify_attachment_id() validation path; the stored payload is later adopted as a WordPress attachment URL and rendered unescaped by wppb_default_fields_make_upload_button() when an administrator views the affected account. CVE record
CVE-2026-93656, 25 Sep 2026
The User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable via a nonce-free GET request to /wp-admin/profile.php, requiring no profile-form submission; a Subscriber can plant the malicious attachment URL, which then executes when an administrator opens that user's Edit User screen. CVE record
CVE-2026-6431, 7 Sep 2026
The User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-75964, 1 Sep 2026
The User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload reaches administrators with the manage_options capability when they visit the Users > Unconfirmed Email Addresses list table and interact with row-action links, as the poisoned javascript: href is rendered verbatim into the page HTML by row_actions(). CVE record
CVE-2026-75965, 1 Sep 2026
The User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode Attribute in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the wppb_toolbox_shortcodes_settings[format-date] option to be set to 'yes' by an administrator for the shortcode to be active and the vulnerability to be exploitable. CVE record
CVE-2026-76547, 29 Aug 2026
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is present in the User Profile Builder WordPress plugin before 4.0.1 itself, so further impact requires a suitable gadget from another installed User Profile Builder WordPress plugin before 4.0.1 or . CVE record
CVE-2026-76548, 29 Aug 2026
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users. CVE record
CVE-2026-76546, 29 Aug 2026
The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by default. CVE record
CVE-2026-15826, 15 Aug 2026
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check - when a registration is submitted with a 61-70 character username, WordPress core rejects it with a WP_Error object, but absint() coerces that object to the integer 1 before the error check can short-circuit execution, causing the plugin to bind and return a transient-backed autologin nonce tied to user ID 1. This makes it possible for unauthenticated attackers to log in as the site's Administrator account (user ID 1), resulting in full administrative takeover of the site. CVE record
CVE-2026-15368, 1 Aug 2026
The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration. CVE record
CVE-2026-3139, 31 Mar 2026
The User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to reassign ownership of arbitrary posts and attachments by changing 'post_author'. CVE record
CVE-2025-15030, 2 Feb 2026
The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account CVE record
CVE-2025-13054, 19 Nov 2025
The User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-8896, 16 Aug 2025
The User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_communication_preferences[]' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the GDPR Communication Preferences module is enabled and at least one GDPR Communication Preferences field has been added to the edit profile form. CVE record
CVE-2025-4671, 3 Jun 2025
The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-6708, 15 May 2025
The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks. CVE record
CVE-2025-2314, 16 Apr 2025
The User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The issue was partially patched in version 3.13.6 of the plugin, and fully patched in 3.13.7. CVE record
CVE-2024-12738, 7 Jan 2025
The User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user meta parameters in all versions up to, and including, 3.12.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page and clicks a link to show user meta. CVE record
CVE-2024-6366, 29 Jul 2024
The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP. CVE record
CVE-2024-0324, 5 Feb 2024
The User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all versions up to, and including, 3.10.8. This makes it possible for unauthenticated attackers to enable or disable the 2FA functionality present in the Premium version of the plugin for arbitrary user roles. CVE record
CVE-2023-6504, 11 Jan 2024
The User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wppb_toolbox_usermeta_handler function in all versions up to, and including, 3.10.7. This makes it possible for authenticated attackers, with contributor-level access and above, to expose sensitive information within user metadata. CVE record
CVE-2023-4059, 4 Sep 2023
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog CVE record
CVE-2023-2297, 27 Apr 2023
The Profile Builder - User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (wppb_front_end_password_recovery). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-0814, or another vulnerability like SQL Injection in another plugin or theme installed on the site to successfully exploit this vulnerability. CVE record
CVE-2023-0814, 14 Feb 2023
The Profile Builder - User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This makes it possible for authenticated attackers, with subscriber-level permissions, and above to retrieve sensitive user meta that can be used to gain access to a high privileged user account. This does require the Usermeta shortcode be enabled to be exploited. CVE record
CVE-2021-36915, 11 Oct 2022
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on. CVE record
CVE-2022-0884, 4 Apr 2022
The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which could allow high privilege user such as admin to perform Criss-Site Scripting attacks even when unfiltered_html is disallowed CVE record
CVE-2022-0653, 24 Feb 2022
The Profile Builder - User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1. CVE record
CVE-2021-24527, 16 Aug 2021
The User Registration & User Profile - Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example. CVE record
CVE-2021-24448, 2 Aug 2021
The User Registration & User Profile - Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue CVE record
CVE-2015-9337, 22 Aug 2019
The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX. CVE record
CVE-2014-10380, 21 Aug 2019
The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms. CVE record
CVE-2015-9328, 21 Aug 2019
The profile-builder plugin before 2.2.5 for WordPress has XSS. CVE record
CVE-2016-10911, 21 Aug 2019
The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues. CVE record

What to do if you run User Profile Builder

If you run User Profile Builder, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new User Profile Builder vulnerabilities

Free. We email you when a new vulnerability is published for User Profile Builder, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support