Description
WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently gain administrative privileges. WordPress Plugin User Profile Builder-Beautiful User Registration Forms, User Profiles & User Role Editor version 3.1.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.1.1 or latest
References
https://twitter.com/NomanRiffat/status/1226966011280314370
https://plugins.svn.wordpress.org/profile-builder/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WooCommerce Address Book Cross-Site Request Forgery (1.5.6)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0093)
Django Improper Input Validation Vulnerability (CVE-2012-4520)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6335)