SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76546

MEDIUM · CVSS 6.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The User Profile Builder plugin for WordPress versions prior to 4.0.1 is vulnerable to Stored Cross-Site Scripting (XSS) due to improper output escaping of an optional shortcode, potentially allowing contributors to execute malicious scripts against any user, including administrators. This vulnerability poses a significant risk to user data integrity and site security. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-76546
Severity
MEDIUM
CVSS
6.8
EPSS
0.24%
WordPress

Original NVD Description

The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by default.