CVE-2023-4059


Profile Builder < 3.9.8 - Unauthenticated Plugin's Pages Creation

The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog



We have discovered 56 live websites that are affected by CVE-2023-4059.

Contact us to get more info




Affected Software

Product  Profile Builder
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 3.9.8
Total Vulnerable Versions52
Vulnerable Domains56 live websites (25.57% of Profile Builder install base)


Common Weakness Enumeration


CWE-862 Missing Authorization



Details

  • Published - Sep 4, 2023
  • Updated - Sep 4, 2023

Credits

  • Mesh3l_911 (finder)
  • WPScan (coordinator)





Countries

United States20 websites



GB6 websites
Spain4 websites
Italy4 websites
Germany3 websites
Brazil2 websites
France2 websites
Austria1 websites
Australia1 websites
Belgium1 websites

TLDs

.com18 websites
.org13 websites
.co.uk2 websites
.com.br2 websites
.de2 websites
.es2 websites
.it2 websites
.at1 websites
.be1 websites
.co1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2023-4059

Top websites that are affected by CVE-2023-4059. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.co Canada**,***
***************.org United States***,***
***.******.org United States***,***
*******.org Spain***,***
********************.com United States***,***
***********.com GB***,***
***.*********.org United States***,***
***.************.org United States***,***
***.*************.de Germany***,***
************.org Germany***,***
See full domain list