CVE-2026-76546: Profile Builder < 4.0.1 - Contributor+ Stored XSS via Format Date Shortcode
The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by default.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress User Profile Builderto a version that resolves this vulnerability.Fixed in 4.0.1
Event History
Frequently Asked Questions
Who can exploit this issue, and who is at risk from viewing the result?
A user with at least the Contributor role can exploit the issue. Any user who views the affected content can be targeted, including administrators.
Are default installations affected?
The vulnerable shortcode is optional and is not enabled by default. Installations are affected only if that shortcode has been enabled and the plugin version is earlier than 4.0.1.
What should be prioritized if an immediate update is not possible?
Disable the optional vulnerable shortcode and restrict Contributor access where possible. Review content created by Contributor-level users for use of the affected shortcode, since malicious script may persist in stored content.