CVE-2026-27413: WordPress Profile Builder Pro plugin < 3.14.0 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14.0.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro profile-builder-pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a through < 3.14.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27413?
CVE-2026-27413 has a high severity rating due to its potential for exploiting SQL Injection vulnerabilities.
How do I fix CVE-2026-27413?
To fix CVE-2026-27413, update the Profile Builder Pro plugin to the latest version beyond 3.13.9.
What type of vulnerability is CVE-2026-27413?
CVE-2026-27413 is an SQL Injection vulnerability that allows attackers to execute blind SQL queries.
Who is affected by CVE-2026-27413?
Users of Profile Builder Pro versions up to and including 3.13.9 are affected by CVE-2026-27413.
Can CVE-2026-27413 lead to data exposure?
Yes, CVE-2026-27413 can potentially lead to unauthorized access and exposure of sensitive database information.