cozmoslabs Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with cozmoslabs products.
Products
- User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor11 vulnerabilities
- Paid Member Subscriptions10 vulnerabilities
- Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction7 vulnerabilities
- Profile Builder Pro6 vulnerabilities
- profile_builder6 vulnerabilities
- Profile Builder3 vulnerabilities
- paid_member_subscriptions2 vulnerabilities
- TranslatePress2 vulnerabilities
- TranslatePress – Translate Multilingual sites with AI Translation2 vulnerabilities
- User Profile Picture2 vulnerabilities
- WP Webhooks2 vulnerabilities
- Profile Builder – User Profile & User Registration Forms1 vulnerability
- Profile Builder – User Profile & User Registration Forms (WordPress plugin)1 vulnerability
- user_profile_picture1 vulnerability
- WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-66701MEDIUM | WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerabilityUnauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. CWE-862Aug 6, 2026 | CVSS5.3v3.1 | EPSS0.184% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-18510HIGH | TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Comment ContentThe TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation may delay exploitation for first-tim… CWE-79Aug 6, 2026 | CVSS7.2v3.1 | EPSS0.243% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-17505MEDIUM | TranslatePress <= 3.2.5 - Reflected Cross-Site ScriptingThe Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replacing the plugin's internal #!trpst# and #!trpen# marker tokens with literal angle brackets across the entire HTML page output after WordPress has already sanitized and escaped user input — allowing the attacker to bypass WordPress's normal HTML escapin… | CVSS6.1v3.1 | EPSS0.804% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-59539HIGH | WordPress Paid Member Subscriptions plugin <= 3.0.7 - Insecure Direct Object References (IDOR) vulnerabilitySubscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. CWE-639Jul 27, 2026 | CVSS7.5v3.1 | EPSS0.323% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object References (IDOR) vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Profile Picture: from n/a through <= 2.6.3. CWE-639Jul 13, 2026 | CVSS2.7v3.1 | EPSS0.192% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-57348HIGH | WordPress Paid Member Subscriptions plugin <= 3.0.4 - Server Side Request Forgery (SSRF) vulnerabilityUnauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions. CWE-918Jul 2, 2026 | CVSS7.2v3.1 | EPSS0.197% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42385HIGH | WordPress Profile Builder Pro plugin <= 3.15.0 - Cross Site Scripting (XSS) vulnerabilityUnauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions. CWE-79Jun 17, 2026 | CVSS7.1v3.1 | EPSS0.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-39514HIGH | WordPress Paid Member Subscriptions plugin <= 2.17.3 - Reflected Cross Site Scripting (XSS) vulnerabilityUnauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions. CWE-79Jun 15, 2026 | CVSS7.1v3.1 | EPSS0.175% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7647HIGH | Profile Builder Pro <= 3.14.5 - Unauthenticated PHP Object InjectionThe Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter within the wppb_request_users_pins_action_callback() AJAX handler, which lacked any nonce verification, type checking, or input validation before deserialization. Because the handler was registered with both wp_ajax_ and wp_ajax_nopriv_ hooks, it was reachable by… CWE-502May 2, 2026 | CVSS8.1v3.1 | EPSS0.462% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3139MEDIUM | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar FieldThe User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to reassign ownership of arbitrary posts and attachments by changing 'post_author'. CWE-639Mar 31, 2026 | CVSS4.3v3.1 | EPSS0.171% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27413CRITICAL | WordPress Profile Builder Pro plugin < 3.14.0 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14.0. CWE-89Mar 19, 2026 | CVSS9.3v3.1 | EPSS0.378% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68514MEDIUM | WordPress Paid Member Subscriptions plugin <= 2.16.8 - Insecure Direct Object References (IDOR) vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.16.8. CWE-639Feb 20, 2026 | CVSS6.5v3.1 | EPSS0.348% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-15030CRITICAL | User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password ResetThe User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account CWE-269Feb 2, 2026 | CVSS9.8v3.1 | EPSS0.487% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66074CRITICAL | WordPress WP Webhooks plugin <= 3.3.8 - Arbitrary File Upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webhooks: from n/a through <= 3.3.8. CWE-434Dec 18, 2025 | CVSS9.0v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66073HIGH | WordPress WP Webhooks plugin <= 3.3.8 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue affects WP Webhooks: from n/a through <= 3.3.8. CWE-502Nov 21, 2025 | CVSS7.2v3.1 | EPSS0.426% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13054MEDIUM | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeThe User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user … CWE-79Nov 19, 2025 | CVSS6.4v3.1 | EPSS0.181% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58592HIGH | WordPress TranslatePress Plugin <= 2.10.2 - Deserialization of untrusted data VulnerabilityDeserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePress: from n/a through <= 2.10.2. CWE-502Nov 6, 2025 | CVSS8.1v3.1 | EPSS0.374% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-11835MEDIUM | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.16.4 - Missing Authorization to Unauthenticated Arbitrary Member Subscription Auto RenewalThe Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability and validation check on the PMS_AJAX_Checkout_Handler::process_payment() function in all versions up to, and including, 2.16.4. This makes it possible for unauthenticated attackers to trigger stored auto-renew charges for arbitrary members. CWE-862Nov 5, 2025 | CVSS5.3v3.1 | EPSS0.218% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58600MEDIUM | WordPress Paid Member Subscriptions Plugin <= 2.15.9 - Broken Access Control VulnerabilityMissing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.9. CWE-862Sep 3, 2025 | CVSS5.3v3.1 | EPSS0.353% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-8895CRITICAL | WP Webhooks <= 3.3.5 - Unauthenticated Arbitrary File CopyThe WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, and including, 3.3.5. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's server to arbitrary locations. This can be used to copy the contents of wp-config.php into a text file which can then be accessed in a browser to reveal database credentials. CWE-22Aug 21, 2025 | CVSS9.8v3.1 | EPSS0.572% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-54017HIGH | WordPress Paid Member Subscriptions <= 2.15.4 - Local File Inclusion VulnerabilityImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows PHP Local File Inclusion.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.4. CWE-98Aug 20, 2025 | CVSS7.5v3.1 | EPSS0.447% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-8896MEDIUM | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.3 - Authenticated (Subscriber+) Stored Cross-Site ScriptingThe User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_communication_preferences[]' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an in… CWE-79Aug 16, 2025 | CVSS6.4v3.1 | EPSS0.199% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49870HIGH | WordPress Paid Member Subscriptions plugin <= 2.15.1 - SQL Injection VulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows SQL Injection.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.1. CWE-89Jul 4, 2025 | CVSS7.5v3.1 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49292MEDIUM | WordPress Profile Builder plugin <= 3.13.8 - Content Spoofing VulnerabilityImproper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder profile-builder allows Phishing.This issue affects Profile Builder: from n/a through <= 3.13.8. CWE-1284Jun 6, 2025 | CVSS4.3v3.1 | EPSS0.261% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-4671MEDIUM | Profile Builder <= 3.13.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare ShortcodesThe Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and including, 3.13.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Jun 3, 2025 | CVSS6.4v3.1 | EPSS0.247% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |