๐Ÿ” CVE Alert

CVE-2026-7647

HIGH 8.1

Profile Builder Pro <= 3.14.5 - Unauthenticated PHP Object Injection

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter within the wppb_request_users_pins_action_callback() AJAX handler, which lacked any nonce verification, type checking, or input validation before deserialization. Because the handler was registered with both wp_ajax_ and wp_ajax_nopriv_ hooks, it was reachable by completely unauthenticated users. This makes it possible for unauthenticated attackers to inject arbitrary PHP objects into application memory.

CWE CWE-502
Vendor cozmoslabs
Product profile builder pro
Published May 2, 2026
Stay Ahead of the Next One

Get instant alerts for cozmoslabs profile builder pro

Be the first to know when new high vulnerabilities affecting cozmoslabs profile builder pro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Cozmoslabs / Profile Builder Pro
0 โ‰ค 3.14.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/c7b897f5-f988-4515-83bc-456f041d7e2e?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/profile-builder-pro/trunk/add-ons/user-listing/one-map-listing.php#L271 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/profile-builder-pro/tags/3.14.5/add-ons/user-listing/one-map-listing.php#L271 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/profile-builder-pro/trunk/add-ons/user-listing/one-map-listing.php#L13 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/profile-builder-pro/tags/3.14.5/add-ons/user-listing/one-map-listing.php#L13

Credits

Mattia Brollo