Plugin Vulnerability Hub
Plugin 31 known issues Latest disclosed Mar 30, 2026

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Vulnerabilities

Review known vulnerability records for the WordPress plugin User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor (`profile-builder`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-3139, CVE-2025-15030 and CVE-2025-13054, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
31
High or Critical
10
Patch Coverage
100%
Last Updated
Mar 31, 2026
Related Security Guides

Use these guides while reviewing User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
28
1. Match the Package
Confirm the installed WordPress plugin slug is profile-builder before acting on any CVE from this cluster.
2. Sort by Severity
Start with 10 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
31 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
28
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2025-15030
User Profile Builder <= 3.15.1 - Unauthenticated Privilege Escalation via Account Ta...
Privilege Escalation Versions up to 3.15.1 3.15.2 CVSS 9.8
CVE-2024-6695
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role...
Vulnerability Versions up to 3.11.8 3.11.9 CVSS 9.8
CVE-2023-2297
Profile Builder – User Profile & User Registration Forms <= 3.9.0 - Insecure Passwor...
SQL Injection Versions up to 3.9.0 3.9.1 CVSS 9.8
CVE-2021-24527
Profile Builder <= 3.4.8 - Admin Access via Password Reset
Vulnerability Versions before 3.4.9 3.4.9 CVSS 9.8
CVE-2021-36915
Profile Builder – User Profile & User Registration Forms <= 3.6.4 - Cross-Site Reque...
Cross-Site Request Forgery Versions up to 3.6.4 3.6.5 CVSS 8.8
CVE-2024-0324
User Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via...
Vulnerability Versions up to 3.10.8 3.10.9 CVSS 8.2
CVE-2015-9337
Profile Builder <= 2.1.3 - Missing Access Controls
Vulnerability Versions up to 2.1.3 2.1.4 CVSS 7.5
CVE-2023-47669
Profile Builder <= 3.10.3 - Cross-Site Request Forgery via pms-cross-promotion.php
Cross-Site Request Forgery Versions up to 3.10.3 3.10.4 CVSS 7.1
CVE-2025-15030 Critical 3.15.2
CVE-2025-15030 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Privilege Escalation

User Profile Builder <= 3.15.1 - Unauthenticated Privilege Escalation via Account Takeover

CVE-2024-6695 Critical 3.11.9
CVE-2024-6695 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Vulnerability

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.8 - Authentication Bypass

CVE-2023-2297 Critical 3.9.1
CVE-2023-2297 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor SQL Injection

Profile Builder – User Profile & User Registration Forms <= 3.9.0 - Insecure Password Reset Mechanism

CVE-2021-24527 Critical 3.4.9
CVE-2021-24527 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Vulnerability

Profile Builder <= 3.4.8 - Admin Access via Password Reset

CVE-2021-36915 High 3.6.5
CVE-2021-36915 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Cross-Site Request Forgery

Profile Builder – User Profile & User Registration Forms <= 3.6.4 - Cross-Site Request Forgery

CVE-2024-0324 High 3.10.9
CVE-2024-0324 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Vulnerability

User Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update

CVE-2015-9337 High 2.1.4
CVE-2015-9337 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Vulnerability

Profile Builder <= 2.1.3 - Missing Access Controls

CVE-2023-47669 High 3.10.4
CVE-2023-47669 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Cross-Site Request Forgery

Profile Builder <= 3.10.3 - Cross-Site Request Forgery via pms-cross-promotion.php

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
31 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
5 critical and 5 high severity findings.
Recent CVEs
CVE-2026-3139, CVE-2025-15030 and CVE-2025-13054
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

CVE-2026-3139 Medium Patch path listed

CVE-2026-3139: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and i...

Published
Mar 30, 2026
Patch Status
3.15.6
CVE-2025-13054 Medium Patch path listed

CVE-2025-13054: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed s...

Published
Nov 18, 2025
Patch Status
3.14.9
Known Vulnerabilities

Reports for User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-3139
CVE-2026-3139: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value() function due to missing validation on a...

Published
Mar 30, 2026
Patched Release
3.15.6
Affected Versions
Versions up to 3.15.5
Next Step
Update to 3.15.6 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-15030
CVE-2025-15030: User Profile Builder <= 3.15.1 - Unauthenticated Privilege Escalation via Account Takeover

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.15.1. This is due to the plugin not properly validating a user's...

Published
Jan 12, 2026
Patched Release
3.15.2
Affected Versions
Versions up to 3.15.1
Next Step
Update to 3.15.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13054
CVE-2025-13054: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitizati...

Published
Nov 18, 2025
Patched Release
3.14.9
Affected Versions
Versions up to 3.14.8
Next Step
Update to 3.14.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-8896
CVE-2025-8896: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_communication_preferences[]' parameter in all versions up to, and including, 3.14.3 due to insufficient i...

Published
Aug 15, 2025
Patched Release
3.14.4
Affected Versions
Versions up to 3.14.3
Next Step
Update to 3.14.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-49292
CVE-2025-49292: Profile Builder <= 3.13.8 - Unauthenticated Content Spoofing

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Content Spoofing in all versions up to, and including, 3.13.8. This makes it possible for unauthenticated attackers to spoof content.

Published
Jun 05, 2025
Patched Release
3.13.9
Affected Versions
Versions up to 3.13.8
Next Step
Update to 3.13.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-4671
CVE-2025-4671: Profile Builder <= 3.13.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes

The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...

Published
Jun 02, 2025
Patched Release
3.13.9
Affected Versions
Versions up to 3.13.8
Next Step
Update to 3.13.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-2314
CVE-2025-2314: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13.5 due to insufficient input sanitization and out...

Published
Apr 15, 2025
Patched Release
3.13.7
Affected Versions
Versions up to 3.13.6
Next Step
Update to 3.13.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-12738
CVE-2024-12738: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.9 - Unauthenticated Stored Cross-Site Scripting

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user meta parameters in all versions up to, and including, 3.12.9 due to insufficient input sanitization an...

Published
Jan 06, 2025
Patched Release
3.13.0
Affected Versions
Versions up to 3.12.9
Next Step
Update to 3.13.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-6708
CVE-2024-6708: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.1 - Authenticated (Admin+) Stored Cross-Site Scripting

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.12.1 due to insufficient input sanitization and output escap...

Published
Aug 13, 2024
Patched Release
3.12.2
Affected Versions
Versions up to 3.12.1
Next Step
Update to 3.12.2 or newer if supported.
Plugin Critical Patched: Yes CVE-2024-6695
CVE-2024-6695: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.8 - Authentication Bypass

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.11.8. This is due to the plugin not properly handling the user registration flow and...

Published
Jul 10, 2024
Patched Release
3.11.9
Affected Versions
Versions up to 3.11.8
Next Step
Update to 3.11.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-6366
CVE-2024-6366: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.7 - Missing Authorization to Unauthenticated Media Upload

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized file uplloads due to a missing capability check on the wppb_upload_file_type() function in all versions up to, and including, 3.11.7....

Published
Jul 08, 2024
Patched Release
3.11.8
Affected Versions
Versions up to 3.11.7
Next Step
Update to 3.11.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-31341
CVE-2024-31341: Profile Builder <= 3.11.2 - Restricted Email Bypass

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to restricted email domain bypass in all versions up to, and including, 3.11.2. This makes it possible for unauthenticated attackers to register with...

Published
Apr 05, 2024
Patched Release
3.11.3
Affected Versions
Versions up to 3.11.2
Next Step
Update to 3.11.3 or newer if supported.