Impact
The User Profile Builder plugin for WordPress is vulnerable to stored cross‑site scripting through the Biographical Info meta field. Insufficient input sanitization and output escaping allow attackers to embed malicious scripts that are stored and later executed whenever a user loads an affected page. This flaw enables arbitrary code execution in the victim’s browser and can lead to session hijacking, defacement, or the execution of additional malicious payloads. The weakness is a classic input‑validation flaw indexed as CWE‑79.
Affected Systems
All WordPress installations running User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor version 3.15.7 or earlier are affected. The vulnerability persists across all releases up to and including 3.15.7 and is present in any site that uses the Biographical Info meta field via the plugin’s front‑end form.
Risk and Exploitability
With a CVSS score of 7.2 the flaw carries a high severity rating. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is by submitting a crafted value to the Biographical Info field using the plugin’s unauthenticated‑accessible form; the malicious payload is then stored and delivered to any user who views a page containing the user profile.
OpenCVE Enrichment