Description
WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently gain administrative privileges. WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor version 3.1.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.1.1 or latest
References
https://twitter.com/NomanRiffat/status/1226966011280314370
https://plugins.svn.wordpress.org/profile-builder/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery SQL Injection (1.5.30)
WebLogic CVE-2018-3197 Vulnerability (CVE-2018-3197)
WordPress Plugin BackWPup Multiple Local File Include Vulnerabilities (1.5.2)
WordPress Plugin Front-end Editor 'upload.php' Arbitrary File Upload (2.2.1)
WordPress Plugin Register Plus 'wp-login.php' Multiple Cross-Site Scripting Vulnerabilities (3.5.1)