Impact
The detected vulnerability is an unauthenticated broken access control flaw in WordPress Profile Builder versions up to 3.16.5. Attackers can bypass permission checks to read or modify user profile information. This flaw can lead to unauthorized disclosure or tampering of personal data. It falls under CWE‑862, which represents improper authorization.
Affected Systems
The flaw affects the Profile Builder plugin developed by Cozmoslabs, a WordPress component. All installations running plugin version 3.16.5 or earlier are potentially vulnerable, regardless of site size or configuration.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. No EPSS data is available and the vulnerability is not listed in CISA's KEV catalog, suggesting low known exploitation activity so far. However, because the attack requires no authentication and targets a common plugin, the risk remains significant for sites that rely on the plugin for user management. Exploitation would likely involve sending crafted requests to the plugin’s endpoints to elevate privileges or extract profile data.
OpenCVE Enrichment