Impact
The User Profile Builder WordPress plugin before 4.0.1 fails to validate the type of data it deserializes when an administrator imports a configuration file, creating a PHP Object Injection vulnerability. This is a CWE‑502 (Deserialization of Untrusted Data) weakness. An attacker with administrative privileges can embed malicious PHP objects in the upload payload, which are then unserialized without restriction.
Affected Systems
Any WordPress site that has installed the User Profile Builder plugin version older than 4.0.1, including the free add‑on component that is disabled by default but can be enabled by administrators, is affected. The vulnerability applies only while the import/export feature is available and enabled.
Risk and Exploitability
The exploitation requires an attacker to first locate a site where an administrator has access to the import function, craft a malicious configuration file, and then rely on a suitable gadget supplied by another installed User Profile Builder plugin or a different vulnerable component, because the core plugin lacks a direct gadget chain. The EPSS score is not available, the CVSS metric is undefined, and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation frequency is uncertain. However, the privileged attack vector and the possibility of gadget availability mean that high‑risk production sites should treat this as a serious threat.
OpenCVE Enrichment