CVE-2026-6431
Stored XSS in User Profile Builder WordPress plugin (Biographical Info field)
CVE-2026-6431 is a stored Cross-Site Scripting vulnerability (CWE-79) in the User Profile Builder WordPress plugin, caused by insufficient input sanitization and output escaping of the 'Biographical Info' meta field parameter. An unauthenticated attacker can submit malicious web script through that field, and the injected script is stored and then executes in the browser of any user who views a page where the injected content is rendered. Successful exploitation allows the attacker to run arbitrary JavaScript in victims' sessions, potentially enabling session hijacking, tampering with profile-bearing pages, or driving privileged users into unintended actions; the flaw is rated 7.2 (High) on CVSS 3.1 with scope changed. All WordPress sites running User Profile Builder in versions up to and including 3.15.7 are affected. As of this analysis there is no public proof-of-concept, the EPSS probability of exploitation within 30 days is low (0.2%, 15th percentile), the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Update the User Profile Builder plugin to a fixed release as soon as one is published - any version newer than 3.15.7 - since no specific fixed version number was provided in the source data. Until the update is applied, restrict who can populate the Biographical Info field on the site and review pages that render that field (user profiles, author archives, member directories) for unexpected scripts. No documented workarounds exist, so treat the upgrade as the primary remediation.
| User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor (WordPress plugin) | All versions up to and including 3.15.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.