{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awordpressuser_profile_builder/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:user_profile_builder:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-95866"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["User Profile Builder (\u003c= 4.0.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe User Profile Builder plugin for WordPress (versions 4.0.2 and earlier) contains a critical stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2026-95866. The flaw exists within the avatar upload functionality, specifically inside the wppb_save_avatar_value() function. Attackers can leverage a zero-length multipart file branch to bypass existing attachment ID validation routines (wppb_save_attachment_id() and wppb_verify_attachment_id()). By injecting arbitrary script payloads into the avatar field, the data is saved directly into user meta. When an administrator subsequently views the compromised user profile, the payload is rendered by the wppb_default_fields_make_upload_button() function without proper output escaping, leading to script execution within the administrator's browser session. This vulnerability poses a significant risk to WordPress site integrity, as it allows attackers to perform unauthorized actions on behalf of administrators.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator's browser session. This can result in unauthorized administrative actions, account takeover, or the injection of malicious content into the site. The vulnerability affects all users of the User Profile Builder plugin version 4.0.2 and below.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of the User Profile Builder plugin to the latest secure version addressing CVE-2026-95866. If an immediate update is not feasible, restrict access to user registration or avatar upload forms via web application firewall rules. Detection teams should monitor web server logs for suspicious POST requests targeting avatar upload endpoints, specifically looking for anomalous content in file upload parameters.\u003c/p\u003e\n","date_modified":"2026-09-25T10:52:43Z","date_published":"2026-09-25T10:52:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-95866/","summary":"The User Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via improper avatar upload sanitization, allowing unauthenticated attackers to execute malicious scripts in administrative contexts.","title":"Stored XSS in User Profile Builder WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-95866/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wordpress:user_profile_builder:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}