Stored Cross-Site Scripting Vulnerability in User Profile Builder Plugin for WordPress
CVE-2025-8896
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2025
What is CVE-2025-8896?
The User Profile Builder plugin, utilized for facilitating user registration and profile management on WordPress sites, contains a vulnerability in the 'gdpr_communication_preferences[]' parameter. This vulnerability arises from inadequate input sanitization and output escaping, thereby allowing authenticated users with Subscriber-level access and up to inject harmful web scripts into web pages. The malicious scripts can execute when other users access affected pages. This issue is particularly significant when the GDPR Communication Preferences module is activated and if at least one preference field is included in the profile edit form.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
User Profile Builder β Beautiful User Registration Forms, User Profiles & User Role Editor * <= 3.14.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved