Cozmoslabs security patch release for CVE-2026-15826
Security Patch Release
Summary
Hide ▲
Show ▼
Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw in versions up to and including 3.16.4 that could let unauthenticated attackers reach an administrator session on vulnerable configurations. Site owners should update to 3.16.5 or later to remove the exposure.
Related Happenings
WordPress security patch release for CVE-2026-64638
Security Patch Release
H score34
First: 07.08.2026 15:56
Last: 07.08.2026 15:56
Sources 1
About this happening:
WordPress 7.0.3 shipped a security fix for CVE-2026-64638, and the release was backported through the 4.7 branch. WordPress urged operators to update immediately a...
WordPress security patch release for CVE-2026-64638
Security Patch ReleaseAbout this happening: WordPress 7.0.3 shipped a security fix for CVE-2026-64638, and the release was backported through the 4.7 branch. WordPress urged operators to update immediately a...
Zoom security patch release for CVE-2026-53412
Security Patch Release
H score43
First: 15.07.2026 23:16
Last: 15.07.2026 23:16
Sources 1
About this happening:
Zoom released Windows security patches covering CVE-2026-53412 and three additional flaws across Zoom Workplace, Windows VDI, Zoom Rooms, Contact Center, a...
Zoom security patch release for CVE-2026-53412
Security Patch ReleaseAbout this happening: Zoom released Windows security patches covering CVE-2026-53412 and three additional flaws across Zoom Workplace, Windows VDI, Zoom Rooms, Contact Center, a...
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch Release
H score29
First: 14.07.2026 16:48
Last: 14.07.2026 16:48
Sources 1
About this happening:
RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch ReleaseAbout this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
Gitea Docker images security update (CVE-2026-20896)
Security Patch Release
H score51
First: 06.07.2026 19:28
Last: 06.07.2026 19:28
Sources 1
About this happening:
Gitea released version 1.26.3 to fix CVE-2026-20896, closing a critical authentication-bypass risk in Gitea Docker images. The update removed the default "*" wildc...
Gitea Docker images security update (CVE-2026-20896)
Security Patch ReleaseAbout this happening: Gitea released version 1.26.3 to fix CVE-2026-20896, closing a critical authentication-bypass risk in Gitea Docker images. The update removed the default "*" wildc...
Google security patch release for CVE-2026-10881
Security Patch Release
H score26
First: 06.06.2026 10:28
Last: 06.06.2026 10:28
Sources 1
About this happening:
Google shipped Chrome 149 with patches for 429 security bugs, including CVE-2026-10881 in ANGLE, creating a broad browser update for users on Linux, Windows, and...
Google security patch release for CVE-2026-10881
Security Patch ReleaseAbout this happening: Google shipped Chrome 149 with patches for 429 security bugs, including CVE-2026-10881 in ANGLE, creating a broad browser update for users on Linux, Windows, and...
Timeline
-
17.08.2026 16:30 1 articles · 2h ago
Wordfence receives vulnerability report for CVE-2026-15826 in User Profile Builder
Initial DisclosureWordfence received a vulnerability report about an authentication bypass in the User Profile Builder plugin tracked as CVE-2026-15826, exposing more than 40,000 WordPress sites to administrator-account access on vulnerable configurations.
Show sources
- WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — www.infosecurity-magazine.com — 17.08.2026 16:30
-
17.08.2026 16:30 1 articles · 2h ago
Wordfence validates type confusion in User Profile Builder registration flow
Technical Analysis UpdateWordfence validated the flaw the following day and traced it to a type confusion error in User Profile Builder’s registration and automatic-login flow, where a failed account-creation result could be converted into an integer and treated as user ID 1, allowing an attacker to obtain an administrator session when the affected site used that configuration.
Show sources
- WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — www.infosecurity-magazine.com — 17.08.2026 16:30
-
17.08.2026 16:30 2 articles · 2h ago
Cozmoslabs releases User Profile Builder 3.16.5 to fix CVE-2026-15826
Mitigation Patch UpdateCozmoslabs acknowledged the report and released User Profile Builder version 3.16.5 to address CVE-2026-15826, with affected site owners advised to update to version 3.16.5 or later to remove the vulnerable code path.
Show sources
- WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — www.infosecurity-magazine.com — 17.08.2026 16:30
- WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — www.infosecurity-magazine.com — 17.08.2026 16:30