CVE-2024-31341: WordPress User Profile Builder plugin <= 3.11.2 - Bypass Vulnerability vulnerability
Published May 17, 2024
·Updated
Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.
Affected Software
2 affected components
Cozmoslabs Profile Builder<=3.11.2
WordPress User Profile Builder<=3.11.2
Remediation
Information
Update to 3.11.3 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:19 AM
Data Sourced
via MITRE·08:19 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31341?
The severity of CVE-2024-31341 is categorized as a medium risk due to its potential for functionality bypass.
2
How do I fix CVE-2024-31341?
To fix CVE-2024-31341, you should upgrade Cozmoslabs Profile Builder to version 3.11.3 or later.
3
What versions of Cozmoslabs Profile Builder are affected by CVE-2024-31341?
CVE-2024-31341 affects Cozmoslabs Profile Builder versions from n/a through 3.11.2.
4
What types of attacks can CVE-2024-31341 enable?
CVE-2024-31341 can enable attackers to bypass functionalities intended to secure or validate user data.
5
Is CVE-2024-31341 specific to WordPress?
Yes, CVE-2024-31341 specifically impacts the WordPress User Profile Builder plugin as part of its broader functionality.