Find notable cyber news and cases, enriched with sources, timelines, and signals.

User Profile Builder authentication bypass (CVE-2026-15826)

Vulnerability
First reported
Last updated
Happening score
H score 58
1 unique sources, 1 articles

Summary

Hide ▲

More than 40,000 WordPress sites are exposed to CVE-2026-15826 in User Profile Builder, an authentication bypass that can let unauthenticated attackers obtain an administrator session on affected configurations.

Timeline

  1. 17.08.2026 16:30 2 articles · 2h ago

    Wordfence receives report of CVE-2026-15826 in User Profile Builder

    Initial Disclosure

    Wordfence received a report about CVE-2026-15826 in the User Profile Builder plugin, an authentication bypass affecting versions up to and including 3.16.4 that can let unauthenticated attackers access an administrator account on more than 40,000 WordPress sites when the vulnerable configuration is present.

    Show sources
  2. 17.08.2026 16:30 1 articles · 2h ago

    Wordfence validates a type confusion flaw in the registration flow

    Technical Analysis Update

    Wordfence validated the flaw and found that a failed account-creation operation in User Profile Builder could be converted into an integer before the plugin checked for an error, causing the code to treat the result as user ID 1 and enabling automatic-login token generation for an administrator session.

    Show sources
  3. 17.08.2026 16:30 1 articles · 2h ago

    Cozmoslabs releases User Profile Builder 3.16.5 to fix the authentication bypass

    Mitigation Patch Update

    Cozmoslabs released User Profile Builder version 3.16.5 to address CVE-2026-15826, and affected site owners were told to update to version 3.16.5 or later.

    Show sources