Description
WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently gain administrative privileges. WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor version 3.1.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.1.1 or latest
References
https://twitter.com/NomanRiffat/status/1226966011280314370
https://plugins.svn.wordpress.org/profile-builder/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Forms-Form builder and Contact form Multiple Unspecified Vulnerabilities (1.4.7)
OpenSSL Session Fixation Vulnerability (CVE-1999-0428)
WordPress Plugin Catch Import Export Security Bypass (1.8)
MySQL Cleartext Transmission of Sensitive Information Vulnerability (CVE-2017-3305)
WordPress Plugin Elementor Website Builder Multiple Vulnerabilities (3.16.4)