CVE-2021-36915
Description
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on.
CWE
- CWE-352 — CWE-352 Cross-Site Request Forgery (CSRF)
Affected
- Cozmoslabs / Profile Builder – User Profile & User Registration Forms (WordPress plugin) — v=<= 3.6.0 ≤3.6.0 [affected]
CVSS
- 3.1 score=4.2 severity=MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
References
- https://patchstack.com/database/vulnerability/profile-builder/wordpress-profile-builder-plugin-3-6-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve
- https://wordpress.org/plugins/profile-builder/#developers
Source
cvelistV5-main/cves/2021/36xxx/CVE-2021-36915.json