CVE-2026-95866 | Cozmoslabs User Profile Builder Plugin up to 4.0.2 on WordPress Avatar Field wppb_save_avatar_value cross site scripting

SecurityVulns

A vulnerability marked as problematic has been reported in Cozmoslabs User Profile Builder Plugin up to 4.0.2 on WordPress. This issue affects the function wppb_save_avatar_value of the component Avatar Field. Performing a manipulation results in cross site scripting.

This vulnerability is known as CVE-2026-95866. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More