Known Vulnerabilities for Profile Builder by Cozmoslabs

Listed below are 8 of the newest known vulnerabilities associated with "Profile Builder" by "Cozmoslabs".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-3139 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vuln... Not Provided 2026-03-31 2026-03-31
CVE-2025-49292 Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder profile-builder allows Phishin... Not Provided 2025-06-06 2026-04-01
CVE-2021-36915 Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading t... 4.3 - MEDIUM 2022-10-11 2022-10-13
CVE-2021-24527 The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset t... 9.8 - CRITICAL 2021-08-16 2023-11-07
CVE-2021-24448 The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modif... 4.8 - MEDIUM 2021-08-02 2023-11-07
CVE-2016-10911 The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues. 6.1 - MEDIUM 2019-08-21 2019-08-22
CVE-2015-9337 The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX. 7.5 - HIGH 2019-08-22 2019-08-26
CVE-2015-9328 The profile-builder plugin before 2.2.5 for WordPress has XSS. 6.1 - MEDIUM 2019-08-21 2019-08-22
CVE-2014-10380 The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms. 6.1 - MEDIUM 2019-08-21 2019-08-22
CVE-2014-8492 Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0... 6.1 - MEDIUM 2017-10-06 2017-10-13

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationCozmoslabsProfile Builder3.0.1AllAllAll
ApplicationCozmoslabsProfile Builder3.0.0AllAllAll
ApplicationCozmoslabsProfile Builder2.9.9AllAllAll
ApplicationCozmoslabsProfile Builder2.9.8AllAllAll
ApplicationCozmoslabsProfile Builder2.9.7AllAllAll
ApplicationCozmoslabsProfile Builder2.9.6AllAllAll
ApplicationCozmoslabsProfile Builder2.9.5AllAllAll
ApplicationCozmoslabsProfile Builder2.9.4AllAllAll
ApplicationCozmoslabsProfile Builder2.9.3AllAllAll
ApplicationCozmoslabsProfile Builder2.9.2AllAllAll
ApplicationCozmoslabsProfile Builder2.9.1AllAllAll
ApplicationCozmoslabsProfile Builder2.9.0AllAllAll
ApplicationCozmoslabsProfile Builder2.8.9AllAllAll
ApplicationCozmoslabsProfile Builder2.8.8AllAllAll
ApplicationCozmoslabsProfile Builder2.8.7AllAllAll
ApplicationCozmoslabsProfile Builder2.8.6AllAllAll
ApplicationCozmoslabsProfile Builder2.8.5AllAllAll
ApplicationCozmoslabsProfile Builder2.8.4AllAllAll
ApplicationCozmoslabsProfile Builder2.8.3AllAllAll
ApplicationCozmoslabsProfile Builder2.8.2AllAllAll
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report