CVE-2023-4059: Cozmoslabs Profile Builder

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog

Affected products

  • Cozmoslabs Profile Builder: before 3.9.8 (fixed in 3.9.8)

Published 2023-09-04. Last modified 2026-06-17.