What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin <= 3.10.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin <= 3.10.3 versions.
Explanation of Vulnerability in Simple Terms
User Profile Builder contains a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unauthorized actions on behalf of an authenticated user. The vulnerability requires the victim to visit a malicious webpage while logged into their site. An attacker can modify user profiles, change settings, or perform other administrative actions depending on the victim's role.
What an attacker can do
Perform unauthorized actions (modify profiles, change settings) on behalf of a logged-in user by tricking them into visiting a malicious page.
Potential impact on your site
Users' profiles and site settings can be altered without their knowledge if they visit untrusted links while logged in.
Conditions required to exploit
Victim must be logged into the site and click a malicious link or visit an attacker-controlled webpage.
Key dates
External resources
Related vulnerabilities