« Back to list

Codesmiths

Codesmiths User Profile Builder: vulnerabilities and CVEs

Codesmiths User Profile Builder has 3 published vulnerabilities, 3 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs3
Last 12 months3
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-75964Medium (6.1)0.38%—Sep 1, 2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and…
CVE-2026-76548High (8.2)0.32%—Aug 29, 2026
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list…
CVE-2026-15368High (8.1)0.38%—Aug 1, 2026
The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1078 Valid Accounts1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.