Cozmoslabs has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 6.8 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (5). Most affected products: User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor (3), TranslatePress – Translate Multilingual sites with AI Translation (1), paid-member-subscriptions (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Products
- User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor 3
- TranslatePress – Translate Multilingual sites with AI Translation 1
- paid-member-subscriptions 1
- profile-builder 1
Worst active — by depth score
CVE-2026-95866High· 7.2The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insuffic…40CVE-2026-89412High· 7.2The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and in…40CVE-2026-6431High· 7.2The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and …40CVE-2026-96338Medium· 6.5Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.36CVE-2026-93656Medium· 6.4The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insuffic…35
Cozmoslabs vulnerabilities
CVEs affecting Cozmoslabs, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-96338Medium· 6.5Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.
Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.
CVE-2026-97249Medium· 5.3Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.
Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.
CVE-2026-93656Medium· 6.4The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insuffic…
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insuffic…
CVE-2026-95866High· 7.2The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insuffic…
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insuffic…
CVE-2026-89412High· 7.2The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and in…
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and in…
CVE-2026-6431High· 7.2The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and …
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field parameter in all versions up to, and …