CVE-2024-6695: critical vulnerability in User Profile Builder
profile-builder <= 3.11.8 - Unauthenticated Privilege Escalation
Published
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 9.8epss 0.8%
from disclosure to weapon
Published on NVDJul 31
VulnCheckJul 23
exploitation probability
0.8%top 45% of all CVEs
observed exploitation
yesVulnCheck
it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · User Profile BuilderRelated CVEs — User Profile Builder
In the same product, most dangerous first.
CVE-2024-6366CRITICALUser Profile Builder < 3.11.8 - Unauthenticated Media UploadEPSS 29.0%CVE-2025-15030CRITICALUser Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password ResetEPSS 0.5%CVE-2026-76546MEDIUMProfile Builder < 4.0.1 - Contributor+ Stored XSS via Format Date ShortcodeEPSS 0.4%CVE-2026-76547MEDIUMProfile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/ExportEPSS 0.4%CVE-2026-15368HIGHProfile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login After RegistrationEPSS 0.4%CVE-2024-6708MEDIUMProfile Builder <= 3.12.0 - Admin+ Stored Cross Site ScriptingEPSS 0.3%