Impact
The User Profile Builder plugin for WordPress stores avatar field data without proper input sanitization or output escaping, allowing an unauthenticated attacker to embed malicious scripts into the avatar upload. When a website visitor or administrator loads the page containing the stored avatar URL, the injected script executes in the victim’s browser. This can be used to deface pages, steal session cookies, perform phishing attacks, or load additional malware.
Affected Systems
WordPress sites running the User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin, versions up to and including 4.0.2, developed by cozmoslabs.
Risk and Exploitability
The CVSS base score of 7.2 indicates high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the exploit requires an unauthenticated attacker to submit a specially crafted avatar upload, exploiting a zero‑length multipart file branch that bypasses validation. The lack of authentication barrier makes the attack vector likely straightforward, giving the adversary ready access to inject payloads that run whenever affected pages are viewed.
OpenCVE Enrichment