Impact
The WordPress plugin User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor is affected by a stored XSS flaw that originates from the unescaped 'date' shortcode attribute. Contributing users with sufficient permission can inject malicious JavaScript that is persisted and executed whenever any site visitor loads a page that processes the shortcode. This can lead to theft of credentials stored in the visitor’s browser, defacement of the site, or redirection to malicious domains. The attack gains the same privileges as the compromised user and can bypass existing content‑sanitization controls.
Affected Systems
All installations of cozmoslabs: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor up to and including version 4.0.0. The flaw exists in WordPress environments where the plugin is active and the setting wppb_toolbox_shortcodes_settings[format-date] is enabled. No newer versions are documented as vulnerable.
Risk and Exploitability
With a CVSS score of 6.4 the vulnerability is considered moderate. The EPSS score is not publicly available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated contributor or higher who has the ability to edit the plugin’s shortcode settings. Once the setting is toggled to 'yes' by an administrator, an attacker can insert JavaScript that will execute automatically for any user who loads a page containing the shortcode.
OpenCVE Enrichment