Stored Cross-Site Scripting Vulnerability in PeproDev Ultimate Profile Solutions Plugin for WordPress
CVE-2026-4791
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-4791?
The PeproDev Ultimate Profile Solutions plugin for WordPress has a vulnerability that allows authenticated users with contributor-level access and higher to exploit the logout-url shortcode's 'button' attribute. This flaw arises due to inadequate sanitization and escaping of user-supplied input, enabling attackers to inject harmful web scripts into pages. When other users access these affected pages, the scripts execute in their browsers, leading to potential data theft, session hijacking, or other malicious activities.
Affected Version(s)
PeproDev Ultimate Profile Solutions 0 <= 8.2.36