Description
WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor version 2.4.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.4.1 or latest
References
Related Vulnerabilities
Moodle Improper Authentication Vulnerability (CVE-2014-0214)
WordPress Plugin WP-PostRatings '[ratings]' Shortcode SQL Injection (1.61)
WordPress Plugin WP Visitor Statistics (Real Time Traffic) Cross-Site Scripting (6.4)
WordPress Plugin WP Statistics Cross-Site Scripting (12.6.3)
Joomla URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-21723)