Impact
The vulnerability in the User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin allows authenticated users with contributor level access to inject arbitrary scripts via shortcodes. Because input sanitization and output escaping are insufficient, the malicious code is stored and executed whenever any user views a page containing the compromised shortcode, potentially enabling session hijacking, defacement, or malicious code execution in the user's browser context.
Affected Systems
All installations of the WordPress User Profile Builder plugin by CozmosLabs up to and including version 3.13.5 are affected. Hackers must possess at least contributor privileges to inject the payload, but once injected the script runs for all visitors to the affected page.
Risk and Exploitability
The CVSS score of 6.4 classifies the flaw as moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access and requires the attacker to place a malicious attribute in a shortcode; the stored nature means the exploit persists until the offending data is removed or the plugin is upgraded.
OpenCVE Enrichment
EUVD