CVE-2026-93656 | Cozmoslabs User Profile Builder Plugin up to 4.0.2 on WordPress Avatar Field /wp-admin/profile.php cross site scripting

SecurityVulns

A vulnerability described as problematic has been identified in Cozmoslabs User Profile Builder Plugin up to 4.0.2 on WordPress. This affects an unknown part of the file /wp-admin/profile.php of the component Avatar Field. Such manipulation leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-93656. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More