CVE-2025-49292: WordPress Profile Builder plugin <= 3.13.8 - Content Spoofing Vulnerability
Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder allows Phishing. This issue affects Profile Builder: from n/a through 3.13.8.
Other sources
Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder profile-builder allows Phishing.This issue affects Profile Builder: from n/a through <= 3.13.8.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49292?
CVE-2025-49292 is categorized as a medium severity vulnerability related to improper validation of input.
How do I fix CVE-2025-49292?
To mitigate CVE-2025-49292, update Cozmoslabs Profile Builder to version 3.13.9 or above.
What type of vulnerability is CVE-2025-49292?
CVE-2025-49292 is an improper validation vulnerability that can be exploited for phishing attacks.
Which versions of Profile Builder are affected by CVE-2025-49292?
CVE-2025-49292 affects Profile Builder versions from n/a through 3.13.8.
Can CVE-2025-49292 be exploited remotely?
Yes, CVE-2025-49292 can be exploited remotely due to its nature of improper input validation.