Description
WordPress Plugin Profile Builder-User Profile & User Registration Forms is prone to a security bypass vulnerability. Successfully exploiting this issue may allow an attacker to gain access to the change password functionality and change the password of an arbitrary user, resulting in accessing user account. WordPress Plugin Profile Builder-User Profile & User Registration Forms version 1.1.24 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.26 or latest
References
Related Vulnerabilities
WordPress Plugin Orbit Fox by ThemeIsle Multiple Vulnerabilities (2.10.2)
WordPress Plugin Simple History Information Disclosure (2.7.4)
WordPress Plugin Personalized WooCommerce Cart Page Cross-Site Request Forgery (2.4)
WordPress Plugin Ultimate Addons for Elementor Security Bypass (1.24.1)
WordPress Plugin YITH WooCommerce Advanced Reviews Security Bypass (1.3.9)