7.5
CVE-2026-82607
- EPSS 0.29%
- Veröffentlicht 31.08.2026 02:30:09
- Zuletzt bearbeitet 31.08.2026 20:56:08
- Erkennungen
Cozmoslabs Profile Builder Plugin Avatar Simple Upload AJAX admin-ajax.php wppb_ajax_simple_avatar unrestricted upload
Profile Builder < 3.16.1 - Unauthenticated Limited File Upload
A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 3.16.2 is sufficient to resolve this issue. It is suggested to upgrade the affected component.
Mögliche Gegenmaßnahme
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor: Update to version 3.16.2, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCozmoslabs
≫
Produkt
Profile Builder Plugin
Version
3.16.0
Status
affected
Version
3.16.1
Status
affected
Version
3.16.2
Status
unaffected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
Version
*-3.16.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.209 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@vuldb.com | 5.5 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| cna@vuldb.com | 7.3 | 3.9 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
|
| cna@vuldb.com | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://vuldb.com/vuln/397108
https://vuldb.com/vuln/397108/cti
https://vuldb.com/cve/CVE-2026-82607
https://vuldb.com/submit/892841
https://ciphersecuritylabs.com/research/articles/when-the-browser-is-the-only-bouncer-unauthenticated-media-upload-in-profile-builder
https://www.cozmoslabs.com/docs/profile-builder/free-changelog/
https://www.wordfence.com/threat-intel/vulnerabilities/id/87287221-ee9b-4ca2-bb35-f8945cd58ce7