PT-2024-14981 · WordPress · The User Profile Builder – Beautiful User Registration Forms

Francesco Carlucci

·

Published

2024-01-11

·

Updated

2025-06-03

·

CVE-2023-6504

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress versions up to, and including, 3.10.7
Description The issue is related to unauthorized access of data due to a missing capability check on the wppb toolbox usermeta handler function. This allows authenticated attackers with contributor-level access and above to expose sensitive information within user metadata.
Recommendations For versions up to, and including, 3.10.7, update to a version that includes a fix for the missing capability check on the wppb toolbox usermeta handler function. As a temporary workaround, consider restricting access to the wppb toolbox usermeta handler function to minimize the risk of exploitation.

Fix

IDOR

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-6504

Affected Products

The User Profile Builder – Beautiful User Registration Forms