Impact
The Profile Builder plugin for WordPress is vulnerable to stored XSS through its user_meta and compare shortcodes because the plugin does not properly sanitize or escape user‑supplied attributes. A malicious actor with contributor‑level or higher permissions can insert arbitrary JavaScript into the page, which will execute when any visitor loads the affected page.
Affected Systems
The affected product is User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor from cozmoslabs. All releases up to and including version 3.13.8 are vulnerable; the issue was fixed in later versions.
Risk and Exploitability
With a CVSS score of 6.4 the vulnerability is considered moderate risk, and the EPSS score of less than 1 % indicates a low probability of exploitation at this time. It is not listed in CISA’s KEV catalog. Exploitation requires an authenticated contributor‑level user to inject malicious payloads; once stored, the script runs for any user who views the page, making it a persistent threat for all site visitors.
OpenCVE Enrichment
EUVD