What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.
Explanation of Vulnerability in Simple Terms
Profile Builder Pro versions up to 3.10.0 expose sensitive user information to authenticated attackers. An attacker with a low-privilege account can read data they should not have access to, such as other users' profile details or private fields. The vulnerability requires login but no additional user interaction. Update to a version newer than 3.10.0 to remediate.
What an attacker can do
Read sensitive user profile data and private fields belonging to other users on the site.
Potential impact on your site
User privacy is compromised; authenticated attackers can access profile information they should not see.
Conditions required to exploit
Attacker must have a low-privilege user account (e.g., subscriber or contributor role) on the site.
Key dates
External resources
Related vulnerabilities