CVE-2026-76546: Profile Builder < 4.0.1 - Contributor+ Stored XSS via Format Date Shortcode
The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by default.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress User Profile Builderto a version that resolves this vulnerability.Fixed in 4.0.1