Impact
The User Profile Builder plugin for WordPress contains an access control flaw that lets unauthenticated visitors exploit its front‑end file upload feature. The vulnerability permits listing the site’s media library and editing unpublished posts, pages, and media items belonging to other users. These capabilities expose the integrity of content and media, enabling an attacker to inject or replace files and alter the site’s data without authorization.
Affected Systems
WordPress sites running the User Profile Builder plugin prior to version 4.0.1 are affected. Anyone who has not yet upgraded the plugin should consider the application as vulnerable if the specified plugin is installed.
Risk and Exploitability
An attacker can simply visit the front‑end media upload interface, which is exposed to all visitors, to trigger the exploit. Because the plugin does not verify user roles before allowing uploads or edits, the threat model is a remote, unauthenticated attack with high potential to compromise content integrity. While a CVSS score is not provided in the available data, the lack of authentication checks indicates a high severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment