Input validation vulnerability in Ultimate Profile Builder 3.0

The Ultimate Profile Builder plugin for WordPress is vulnerable to security issues that could allow an attacker to inject malicious scripts into pages. This affects versions of the plugin before 3.0, and is caused by inadequate input sanitization, output escaping, and missing nonce validation. If an attacker can deceive a user into performing an action like clicking a link, these malicious scripts can be executed.

Detected in:

Ultimate Profile Builder open vulnerable versions: >= * < 3.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.