Stored Cross-Site Scripting in User Profile Builder Plugin for WordPress
CVE-2026-93656
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-93656?
The User Profile Builder plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the Avatar Field. This vulnerability allows authenticated users with subscriber-level roles to insert malicious scripts into user profiles, which are then executed when an administrator accesses the affected user's Edit User screen. The exploit can be executed via a nonce-free GET request to /wp-admin/profile.php, enabling the attacker to compromise site security and potentially deliver harmful content to other users.
Affected Version(s)
User Profile Builder β Beautiful User Registration Forms, User Profiles & User Role Editor 0 <= 4.0.2