Description
WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently gain administrative privileges. WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor version 3.1.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.1.1 or latest
References
https://twitter.com/NomanRiffat/status/1226966011280314370
https://plugins.svn.wordpress.org/profile-builder/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Image Optimizer, Resizer and CDN-Sirv Arbitrary File Upload (7.2.6)
WordPress Plugin Access Expiration Cross-Site Scripting (1.1)
WordPress Plugin Contact Bank-Contact Form Builder for WordPress Cross-Site Scripting (3.0.30)
ZenCart Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-11675)