Unauthenticated Access Control Vulnerability in Profile Builder Plugin for WordPress
CVE-2026-66701
5.3MEDIUM
What is CVE-2026-66701?
The Profile Builder plugin for WordPress, up to version 3.16.5, is susceptible to an unauthenticated broken access control vulnerability. This flaw could allow unauthorized users to access sensitive information or gain elevated privileges on the site, potentially leading to data exposure and exploitation.
Affected Version(s)
Profile Builder <= 3.16.5
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program