Junglewise Threat Intelligence

CVE-2026-42385: Cozmoslabs Profile Builder Pro unauthenticated XSS

CVE-2026-42385 · Severity: high · CVSS 7.1 · Published 2026-06-17

Vendors: Cozmoslabs.

Executive brief

Cozmoslabs Profile Builder Pro, a WordPress plugin used for creating user registration and profile forms, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. This issue affects versions up to 3.15.0 and can be exploited without needing a login.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Cozmoslabs Profile Builder Pro plugin for WordPress in versions up to and including 3.15.0. The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This can result in session theft or unauthorized actions performed on behalf of a logged-in administrator. The issue is resolved in version 3.15.1.

Affected products

  • Cozmoslabs Profile Builder Pro <= 3.15.0

Timeline

  • 2026-04-20: other: Vulnerability reported by researcher
  • 2026-04-27: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: CVE published to NVD
  • 2026-04-27: patched: Patch released in version 3.15.1

References