Description
WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create new user accounts with admin privileges. WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor version 2.3.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.6 or latest
References
Related Vulnerabilities
PHP Numeric Errors Vulnerability (CVE-2006-4486)
WebLogic Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-21350)
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-4614)
Oracle Application Server Other Vulnerability (CVE-2004-1362)
WordPress Plugin Redux Framework Cross-Site Scripting (4.4.17)