PatchSiren

cozmoslabs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH cozmoslabs CVE published 2026-09-07

CVE-2026-6431

The User Profile Builder plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the 'Biographical Info' meta field parameter in all versions up to, and including, 3.15.7. This allows unauthenticated attackers to inject web scripts that execute when a user accesses an injected page. The vulnerability was reported by [email protected] and is documented in the CVE Program record and NV [truncated]

MEDIUM Cozmoslabs CVE published 2026-08-31

CVE-2026-82607

The Cozmoslabs Profile Builder Plugin up to version 3.16.1 for WordPress contains a medium severity vulnerability (CVSS score of 5.5) related to unrestricted file uploads via the Avatar Simple Upload AJAX Handler. This vulnerability, identified as CVE-2026-82607, can be exploited remotely and has been made public. Users of the affected plugin version should prioritize upgrading to version 3.16.2 or later. [truncated]

MEDIUM Cozmoslabs CVE published 2026-08-06

CVE-2026-66701

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:22.987Z and has not been modified since then. The unauthenticated broken access control vulnerability in Profile Builder plugin version 3.16.5 or earlier poses a significant risk to affected deployments. This vulnerability could potentially allow unauthorized access to user profiles, which [truncated]

HIGH cozmoslabs CVE published 2026-08-06

CVE-2026-18510

The TranslatePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderat [truncated]

HIGH Cozmoslabs CVE published 2026-07-27

CVE-2026-59539

A HIGH severity vulnerability was found in Paid Member Subscriptions plugin version 3.0.7 and earlier. The vulnerability is an Insecure Direct Object References (IDOR) issue, which could allow attackers to access sensitive data. This issue affects users of Paid Member Subscriptions plugin version 3.0.7 and earlier. The vulnerability allows unauthenticated attackers to access sensitive data by manipulating [truncated]

LOW Cozmoslabs CVE published 2026-07-13

CVE-2026-61971

A vulnerability was found in Cozmoslabs User Profile Picture metronet-profile-picture. It has been classified as problematic. Affected is an unknown function of the component User-Controlled Key Handler. The manipulation leads to authorization bypass. The issue affects User Profile Picture: from n/a through <= 2.6.3. This vulnerability allows attackers to bypass authorization due to incorrectly configured [truncated]

HIGH Cozmoslabs CVE published 2026-06-17

CVE-2026-42385

CVE-2026-42385 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Profile Builder Pro versions <= 3.15.0. The vulnerability has a CVSS score of 7.1 and is considered HIGH. It was published on 2026-06-17T13:20:40.067Z and last modified on 2026-06-17T15:16:50.517Z. Users of Profile Builder Pro should update to a patched version to prevent exploitation. The vulnerability allows at [truncated]

HIGH Cozmoslabs CVE published 2026-06-15

CVE-2026-39514

CVE-2026-39514 is a HIGH severity Unauthenticated Cross Site Scripting (XSS) vulnerability affecting Paid Member Subscriptions plugin versions <= 2.17.3. The vulnerability has a CVSS score of 7.1 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-39514). The vulnerability was reported by Patchstack.