Stored Cross-Site Scripting Vulnerability in User Profile Builder Plugin for WordPress
CVE-2026-75964
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-75964?
The User Profile Builder plugin for WordPress has a vulnerability that allows unauthenticated attackers to execute arbitrary web scripts through the 'email' parameter. This is due to a failure to properly sanitize and escape user input. When an administrator accesses the Users > Unconfirmed Email Addresses section and interacts with specific links, malicious scripts may be executed, posing significant risks to site security. Attackers can leverage this vulnerability to craft payloads that affect the administrator's interaction with the application, leading to potential account compromises and data breaches.
Affected Version(s)
User Profile Builder β Beautiful User Registration Forms, User Profiles & User Role Editor 0 <= 4.0.0