CVE-2024-6708: Cozmoslabs Profile Builder
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.
Affected products
- Cozmoslabs Profile Builder: before 3.12.2 (fixed in 3.12.2)
Published 2025-05-15. Last modified 2026-06-17.