Impact
The User Profile Builder plugin performs insufficient input sanitization and output escaping on the avatar field, enabling an authenticated attacker with subscriber‑level or higher privileges to inject malicious script code. When the attacker submits a crafted avatar URL, it is stored and then rendered whenever an administrator opens that user’s Edit User screen, causing the embedded script to run with administrative privileges. This can lead to defacement, credential theft, or the execution of arbitrary commands within the WordPress environment.
Affected Systems
Any WordPress installation using the User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin, of version 4.0.2 or earlier, is affected. Subscribers and any role with equal or higher permissions can input the payload, and administrators are the final targets when they view edited profiles.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity vulnerability. No EPSS score is available, and the issue is not listed in CISA’s KEV catalog, implying a moderate risk of exploitation. However, the attack requires an authenticated user with at least subscriber privileges to upload the malicious avatar, and the exploit succeeds only when an administrator subsequently accesses the Edit User screen. Consequently, while the vulnerability does not allow arbitrary code execution from the open web, it can be leveraged by internal users with basic authoring rights to impact higher‑privileged administrators.
OpenCVE Enrichment