Data Modification Vulnerability in User Profile Builder Plugin for WordPress
CVE-2024-0324
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 5 February 2024
Summary
The User Profile Builder plugin for WordPress is susceptible to unauthorized data modification due to the absence of capability checks within the 'wppb_two_factor_authentication_settings_update' function. This flaw exists in all versions up to and including 3.10.8, allowing unauthenticated attackers to manipulate two-factor authentication (2FA) settings for any user role. As a result, attackers may enable or disable 2FA functionality available in the Premium version, which poses a significant security risk to users relying on this feature for enhanced account protection.
Affected Version(s)
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor * <= 3.10.8
References
EPSS Score
45% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved