PT-2026-98399 · WordPress · User Profile Builder

·

CVE-2026-95866

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor versions prior to 4.0.3
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server. The issue occurs in the wppb save avatar value() function, where a zero-length multipart file branch writes raw request values directly to user meta, bypassing the validation performed by wppb save attachment id() and wppb verify attachment id(). The stored payload is subsequently treated as a WordPress attachment URL and rendered without escaping by the wppb default fields make upload button() function when an administrator views the compromised account.
Recommendations Update User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor to version 4.0.3 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95866

Affected Products

User Profile Builder