{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-30T10:23:05.235","vulnerabilities":[{"cve":{"id":"CVE-2026-3139","sourceIdentifier":"security@wordfence.com","published":"2026-03-31T12:16:31.037","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to reassign ownership of arbitrary posts and attachments by changing 'post_author'."},{"lang":"es","value":"El plugin User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor para WordPress es vulnerable a Referencia Directa a Objeto Insegura en versiones hasta e incluyendo la 3.15.5 a través de la función wppb_save_avatar_value() debido a la falta de validación en una clave controlada por el usuario. Esto hace posible que atacantes autenticados, con acceso de nivel suscriptor y superior, reasignen la propiedad de publicaciones y archivos adjuntos arbitrarios cambiando 'post_author'."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"cozmoslabs","product":"User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.15.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T15:39:36.557641Z","id":"CVE-2026-3139","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/changeset/3481772/profile-builder","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/760f7736-db49-4210-a2f3-3abb506106d7?source=cve","source":"security@wordfence.com"}]}}]}