PT-2026-29224 · Cozmoslabs · The User Profile Builder – Beautiful User Registration Forms

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-3139

CVSS v3.1

4.3

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb save avatar value() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to reassign ownership of arbitrary posts and attachments by changing 'post author'.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-3139

Affected Products

The User Profile Builder – Beautiful User Registration Forms