Impact
The vulnerability is an improper validation of specified quantity in input fields in the Cozmoslabs Profile Builder plugin, which allows an attacker to supply crafted input that can masquerade as legitimate content, enabling phishing attacks. This flaw does not provide direct code execution or privilege escalation but does facilitate deceptive content.
Affected Systems
Affected products are the Cozmoslabs Profile Builder plugin for WordPress. Versions from any version through 3.13.8 are impacted. No other versions or vendors are listed.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate severity. The EPSS score is less than 1%, suggesting a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw is limited to content spoofing and requires user interaction with the plugin’s front‑end forms, the most likely attack vector is a web‑based user injection. Exploitation would involve submitting carefully crafted input via the plugin’s interfaces; mitigation can be achieved by updating the plugin or disabling it.
OpenCVE Enrichment
EUVD