Description
WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor is prone to a security bypass vulnerability. Successfully exploiting this issue may allow an attacker to gain access to the change password functionality and change the password of an arbitrary user, resulting in accessing user account. WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor version 1.1.24 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.26 or latest
References
Related Vulnerabilities
Java Denial of Service (DoS) Vulnerability (CVE-2018-3180)
WordPress 5.4.x Prototype Pollution (5.4 - 5.4.9)
Apache HTTP Server URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-1927)
math.js Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-1001002)
WordPress Plugin WP Social Feed Gallery Unspecified Vulnerability (2.1.1)