Description
The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `logout-url` shortcode's 'button' attribute in all versions up to, and including, 8.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-10-10
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker who can log into the site with a contributor role or higher to insert malicious JavaScript code through the ‘button’ attribute of the logout‑url shortcode. Because the value is stored and later rendered without proper sanitization, the injected script will run in the browser context of any user who views a page containing the modified shortcode. This can lead to defacement, credential theft, or other client‑side attacks. The weakness is a classic stored XSS flaw, classified as CWE‑79.

Affected Systems

PeproDev Ultimate Profile Solutions for WordPress, versions 8.2.36 and earlier. The flaw exists in all releases up to and including 8.2.36, regardless of other plugins or themes installed.

Risk and Exploitability

The CVSS score of 6.4 places the vulnerability in the moderate range; no exploit probability data is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access with contributor‑level capability or higher, meaning the threat is limited to users who have been granted such permissions within the WordPress installation. However, once an attacker gains that level of access, they can affect all other users of the site by injecting scripts that will run across all authenticated sessions. As the vulnerability is a stored XSS, it is readily exploitable if attackers can reach the shortcode interface, and no significant configuration or environmental restrictions are noted.

Generated by OpenCVE AI on October 10, 2026 at 09:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update PeproDev Ultimate Profile Solutions to the latest version (>= 8.2.37) to remove the vulnerability.
  • If an update is not immediately possible, disable the logout‑url shortcode or modify the plugin code to remove the button attribute’s unsanitized handling.
  • Restrict contributor and higher roles to eliminate unnecessary permissions, and review the site’s security policy to ensure only trusted users have access to plugin configuration functions.

Generated by OpenCVE AI on October 10, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `logout-url` shortcode's 'button' attribute in all versions up to, and including, 8.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title PeproDev Ultimate Profile Solutions <= 8.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button' Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T08:26:39.840Z

Reserved: 2026-03-24T21:11:06.306Z

Link: CVE-2026-4791

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T09:16:39.203

Modified: 2026-10-10T09:16:39.203

Link: CVE-2026-4791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')