Sceawere
Vulnerability Detail
CVE-2026-4791UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Ultimate Profile Solutions
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 3h ago
- Vendor
- peprodev
- Product
- PeproDev Ultimate Profile Solutions
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `logout-url` shortcode's 'button' attribute in all versions up to, and including, 8.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T09:16:39.203Z",
"pubdate": "2026-10-10T09:16:39.203Z",
"executiveSummary": "The PeproDev Ultimate Profile Solutions plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability residing within the logout-url shortcode's button attribute.\nThe vulnerability originates from inadequate input sanitization and improper output escaping mechanisms applied to user-supplied attributes, enabling the injection of malicious client-side scripts.\nThis flaw affects all plugin versions up to and including 8.2.36.\nThe impact allows an authenticated attacker, possessing a minimum of contributor-level privileges, to inject arbitrary JavaScript into pages. When a victim views the affected page, the malicious script executes within the context of their session.\nThis cross-site scripting vector can be leveraged for session hijacking, unauthorized actions performed on behalf of the user, redirection to malicious domains, or the exfiltration of sensitive information.\nGiven the nature of stored XSS, the vulnerability carries a significant risk, as the payload remains persistent within the application database and is triggered automatically upon rendering the affected content.",
"technicalDetails": "The root cause of this vulnerability is the failure of the plugin's shortcode handler to validate or sanitize the input provided to the 'button' attribute of the 'logout-url' shortcode before storing it in the database.\nFurthermore, the plugin lacks context-aware output escaping when rendering this attribute back to the browser. As a result, the application treats user-supplied string data as executable HTML/JavaScript rather than plain text.\nThe attack flow begins when an attacker with contributor-level access crafts a malicious post or page containing the 'logout-url' shortcode, embedding a JavaScript payload within the 'button' parameter (e.g., [logout-url button='<script>alert(1)</script>']).\nOnce the post or page is saved, the malicious payload is stored persistently within the WordPress database. No further interaction is required from the attacker to maintain the persistence of the vulnerability.\nWhen any authenticated user (including administrators) or visitor accesses the page where the shortcode is processed, the server-side code renders the stored malicious payload directly into the HTML document's Document Object Model (DOM).\nBecause the payload is not properly neutralized, the victim's browser interprets the injected script as legitimate code originating from the trusted domain. This executes the script in the context of the victim's current session.\nExploitation is facilitated by the fact that the plugin's output logic fails to use appropriate WordPress escaping functions, such as esc_attr(), which would typically neutralize characters like angle brackets, quotes, and ampersands.\nThe post-exploitation impact is severe, as the attacker can gain full access to the victim's session data. By executing JavaScript within the victim's browser, an attacker can steal session cookies, perform unauthorized administrative operations (such as creating new users or modifying site settings), or redirect the victim to phishing pages.\nSince the vulnerability is stored, it effectively turns every affected page into a persistent exploit vector, posing a continuous threat to any user who visits the site."
}