Cross-Site Scripting
14 records42.4%First: 2014. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 33 vulnerability records associated with User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor, published between 2014 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 3 | |
| 2015 | 2 | |
| 2016 | 2 | |
| 2017 | 1 | |
| 2020 | 2 | |
| 2021 | 2 | |
| 2022 | 3 | |
| 2023 | 4 | |
| 2024 | 6 | |
| 2025 | 6 | |
| 2026 | 2 |
| Severity | Records | Share |
|---|---|---|
| Critical | 6 | 18.2% |
| High | 6 | 18.2% |
| Medium | 21 | 63.6% |
First: 2014. Latest: 2025.
First: 2016. Latest: 2026.
First: 2015. Latest: 2026.
First: 2014. Latest: 2024.
First: 2023. Latest: 2025.
First: 2020. Latest: 2020.
First: 2023. Latest: 2023.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.15.63.15.23.14.93.14.43.13.93.13.73.13.03.12.23.11.93.11.83.11.33.10.93.10.83.10.43.9.83.9.13.6.53.6.83.6.23.4.93.4.83.3.33.1.12.5.82.4.22.4.12.2.52.1.42.0.31.1.661.1.60Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.15.5 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field | March 30, 2026 | 3.15.6 | Medium |
*-3.15.1 | User Profile Builder <= 3.15.1 - Unauthenticated Privilege Escalation via Account Takeover | January 12, 2026 | 3.15.2 | Critical |
*-3.14.8 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | November 18, 2025 | 3.14.9 | Medium |
*-3.14.3 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting | August 15, 2025 | 3.14.4 | Medium |
*-3.13.8 | Profile Builder <= 3.13.8 - Unauthenticated Content Spoofing | June 5, 2025 | 3.13.9 | Medium |
*-3.13.8 | Profile Builder <= 3.13.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes | June 2, 2025 | 3.13.9 | Medium |
*-3.13.6 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | April 15, 2025 | 3.13.7 | Medium |
*-3.12.9 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.9 - Unauthenticated Stored Cross-Site Scripting | January 6, 2025 | 3.13.0 | Medium |
*-3.12.1 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.1 - Authenticated (Admin+) Stored Cross-Site Scripting | August 13, 2024 | 3.12.2 | Medium |
*-3.11.8 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.8 - Authentication Bypass | July 10, 2024 | 3.11.9 | Critical |
*-3.11.7 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.11.7 - Missing Authorization to Unauthenticated Media Upload | July 8, 2024 | 3.11.8 | Medium |
*-3.11.2 | Profile Builder <= 3.11.2 - Restricted Email Bypass | April 5, 2024 | 3.11.3 | Medium |
*-3.10.8 | User Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update | January 16, 2024 | 3.10.9 | High |
*-3.10.6 | Profile Builder <= 3.10.7 - Insecure Direct Object Reference to Sensitive Information Exposure via user_meta Shortcode | January 5, 2024 | 3.10.8 | Medium |
*-3.10.3 | Profile Builder <= 3.10.3 - Cross-Site Request Forgery via pms-cross-promotion.php | November 7, 2023 | 3.10.4 | High |
[*, 3.9.8) | Profile Builder <= 3.9.7 - Missing Authorization to Initial Page Creation | August 8, 2023 | 3.9.8 | Medium |
*-3.9.0 | Profile Builder – User Profile & User Registration Forms <= 3.9.0 - Insecure Password Reset Mechanism | February 13, 2023 | 3.9.1 | Critical |
*-3.9.0 | Profile Builder – User Profile & User Registration Forms <= 3.9.0 - Sensitive Information Disclosure via Shortcode | February 13, 2023 | 3.9.1 | Medium |
*-3.6.4 | Profile Builder – User Profile & User Registration Forms <= 3.6.4 - Cross-Site Request Forgery | September 29, 2022 | 3.6.5 | High |
[*, 3.6.8) | Profile Builder <= 3.6.7 - Admin+ Stored Cross-Site Scripting | March 9, 2022 | 3.6.8 | Medium |
*-3.6.1 | Profile Builder - User Profile & User Registration Forms <= 3.6.1 - Cross-Site Scripting via site_url Parameter | February 17, 2022 | 3.6.2 | Medium |
[*, 3.4.9) | Profile Builder <= 3.4.8 - Admin Access via Password Reset | July 19, 2021 | 3.4.9 | Critical |
*-3.4.7 | Profile Builder <= 3.4.7 - Authenticated (Administrator+) Stored Cross-Site Scripting | June 30, 2021 | 3.4.8 | Medium |
[*, 3.3.3) | Profile Builder/Profile Builder Pro <= 3.3.2 - Authenticated Blind SQL Injection | December 4, 2020 | 3.3.3 | High |
[*, 3.1.1) | Profile Builder <= 3.1.0 - Privilege Escalation | February 13, 2020 | 3.1.1 | Critical |
Selected source records
Published: March 30, 2026
Published: January 12, 2026
Published: November 18, 2025
Published: August 15, 2025
Published: June 5, 2025
Published: June 2, 2025
Published: April 15, 2025
Published: January 6, 2025
Published: July 10, 2024
Published: January 12, 2026
Published: July 19, 2021
Published: February 13, 2020
Published: May 6, 2014
Published: February 13, 2023
Published: July 7, 2016
Published: December 4, 2020
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.