CVE-2023-6504: Profile Builder <= 3.10.7 - Insecure Direct Object Reference to Sensitive Information Exposure via user_meta Shortcode
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wppbtoolboxusermetahandler function in all versions up to, and including, 3.10.7. This makes it possible for authenticated attackers, with contributor-level access and above, to expose sensitive information within user metadata.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6504?
CVE-2023-6504 has a high severity as it allows unauthorized access to user data.
How do I fix CVE-2023-6504?
To fix CVE-2023-6504, update the User Profile Builder plugin to version 3.10.8 or higher.
Which versions of User Profile Builder are affected by CVE-2023-6504?
CVE-2023-6504 affects all versions up to and including 3.10.7 of the User Profile Builder plugin.
What data is at risk with CVE-2023-6504?
CVE-2023-6504 poses a risk of unauthorized access to sensitive user profile data.
Is there a specific function vulnerable in CVE-2023-6504?
The vulnerability in CVE-2023-6504 is due to a missing capability check in the wppb_toolbox_usermeta_handler function.