Vulnerability Description
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cozmoslabs | Profile Builder | < 3.9.8 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/fc719d12-2f58-4d1f-b696-0f937e706842Third Party Advisory
- https://wpscan.com/vulnerability/fc719d12-2f58-4d1f-b696-0f937e706842Third Party Advisory
- https://wpscan.com/vulnerability/fc719d12-2f58-4d1f-b696-0f937e706842Third Party Advisory
FAQ
What is CVE-2023-4059?
CVE-2023-4059 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages fr...
How severe is CVE-2023-4059?
CVE-2023-4059 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-4059?
Check the references section above for vendor advisories and patch information. Affected products include: Cozmoslabs Profile Builder.