PT-2024-15470 · WordPress · User Profile Builder

Kodai Kubono

+1

·

Published

2024-02-05

·

Updated

2024-02-13

·

CVE-2024-0324

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress versions up to, and including, 3.10.8
Description The issue is related to a missing capability check on the wppb two factor authentication settings update function, allowing unauthorized modification of data. This enables unauthenticated attackers to enable or disable the 2FA functionality for arbitrary user roles in the Premium version of the plugin.
Recommendations For versions up to, and including, 3.10.8, update to a version later than 3.10.8 to resolve the issue. As a temporary workaround, consider disabling the wppb two factor authentication settings update function until a patch is available.

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-0324

Affected Products

User Profile Builder