CyberRota Analysis
AI-GeneratedThe User Profile Builder plugin for WordPress prior to version 4.0.1 has a vulnerability that improperly restricts its front-end file upload feature, enabling unauthenticated users to access functionalities typically reserved for privileged roles. This flaw allows unauthorized individuals to list the site's media library and modify unpublished content belonging to other users. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized access and content manipulation.
Original NVD Description
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.