CVE-2026-76546
Received Received - Intake

Stored XSS in User Profile Builder WordPress Plugin

Vulnerability report for CVE-2026-76546, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: WPScan

Description

The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by default.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpengine profile_builder to 4.0.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-76546 is a stored Cross-Site Scripting (XSS) vulnerability in the Profile Builder WordPress plugin versions before 4.0.1. It occurs because the plugin does not escape output from one of its optional shortcodes, allowing users with contributor-level access or higher to inject malicious scripts.

Detection Guidance

To detect this vulnerability, check if the Profile Builder WordPress plugin is installed and if its version is prior to 4.0.1. Inspect the plugin's shortcode usage for unescaped output. Review user roles with contributor access or higher for suspicious script injections in posts or pages.

Impact Analysis

Attackers with contributor access or higher can inject malicious scripts into web pages. When other users, including administrators, view the affected content, the scripts execute, potentially stealing sensitive data, session cookies, or performing unauthorized actions on their behalf.

Compliance Impact

This vulnerability could lead to data breaches, compromising personal or sensitive information. For GDPR, it may result in unauthorized access to user data, triggering reporting requirements. For HIPAA, it could expose protected health information, violating compliance standards.

Mitigation Strategies

Immediately update the Profile Builder plugin to version 4.0.1 or later. Disable the affected shortcode if not in use. Audit user roles to ensure no unauthorized contributors have access. Monitor content for injected scripts and remove any detected malicious code.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76546. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart