CVE-2023-4059: Profile Builder < 3.9.8 - Unauthenticated Plugin's Pages Creation
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2023-4059.
What is the affected software for this vulnerability?
The affected software is the Profile Builder WordPress plugin before version 3.9.8.
What is the severity rating of CVE-2023-4059?
The severity rating of CVE-2023-4059 is medium with a score of 4.3.
What is the vulnerability description of CVE-2023-4059?
The Profile Builder WordPress plugin before 3.9.8 lacks authorization and CSRF in its page creation function, allowing unauthenticated users to create the register, log-in, and edit-profile pages from the plugin on the blog.
How can I fix CVE-2023-4059?
To fix CVE-2023-4059, it is recommended to update the Profile Builder WordPress plugin to version 3.9.8 or later.