PT-2026-29224 · WordPress · The User Profile Builder – Beautiful User Registration Forms

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-3139

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor versions prior to 3.15.6
Description The User Profile Builder plugin for WordPress is susceptible to an Insecure Direct Object Reference. This issue stems from a lack of validation on a user-controlled key within the wppb save avatar value() function. Authenticated attackers with subscriber-level access or higher can exploit this to modify the 'post author' field, potentially reassigning ownership of posts and attachments. The vulnerable parameter is post author.
Recommendations Update User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor to version 3.15.6 or later.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-3139

Affected Products

The User Profile Builder – Beautiful User Registration Forms