The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://wordpress.org/plugins/profile-builder/#developers | third party advisory release notes |