Stored Cross-Site Scripting Vulnerability in User Profile Builder Plugin for WordPress
CVE-2026-75964

6.1MEDIUM

What is CVE-2026-75964?

The User Profile Builder plugin for WordPress has a vulnerability that allows unauthenticated attackers to execute arbitrary web scripts through the 'email' parameter. This is due to a failure to properly sanitize and escape user input. When an administrator accesses the Users > Unconfirmed Email Addresses section and interacts with specific links, malicious scripts may be executed, posing significant risks to site security. Attackers can leverage this vulnerability to craft payloads that affect the administrator's interaction with the application, leading to potential account compromises and data breaches.

Affected Version(s)

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor 0 <= 4.0.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.