CVE-2023-6504: Cozmoslabs Profile Builder
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wppb_toolbox_usermeta_handler function in all versions up to, and including, 3.10.7. This makes it possible for authenticated attackers, with contributor-level access and above, to expose sensitive information within user metadata.
Affected products
- Cozmoslabs Profile Builder: up to and including 3.10.7
Published 2024-01-11. Last modified 2026-06-17.