Impact
The User Profile Builder plugin (versions <=3.16.4) contains a type‑confusion vulnerability that allows an attacker to bypass authentication. When a registration form is submitted with a username of 61–70 characters, WordPress core returns a WP_Error, but the plugin converts this error object to the integer 1 before performing an error check, causing it to generate an autologin nonce for user ID 1. The result is that unauthenticated users can log in as the site’s Administrator, providing full control over the WordPress site.
Affected Systems
Vendors: cozmoslabs. Product: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor. The vulnerability affects all installations of the plugin at or below version 3.16.4. No other product versions are impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and the EPSS score of 4% suggests the probability of exploitation is low but non‑zero. The vulnerability is not listed in CISA KEV. Attackers can exploit the flaw without authentication by submitting a crafted registration request, typically from a simple web form. If successful, the attacker obtains administrative privileges, enabling full control over the site’s content, configuration, and users.
OpenCVE Enrichment