Description
WordPress Plugin Profile Builder-User Profile & User Registration Forms is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change the password of arbitrary users. WordPress Plugin Profile Builder-User Profile & User Registration Forms version 1.1.59 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.60 or latest
References
Related Vulnerabilities
MiniMax-Page Layout Builder Arbitrary File Upload (1.7.1)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-4298)
WordPress 5.5.x PHP Object Injection (5.5 - 5.5.4)
Oracle Database Server Other Vulnerability (CVE-2007-3855)
Ruby on Rails Improper Input Validation Vulnerability (CVE-2014-0082)