Find notable cyber news and cases, enriched with sources, timelines, and signals.

User Profile Builder authentication bypass (CVE-2026-15826)

Vulnerability
First reported
Last updated
Happening score
H score 58
2 unique sources, 2 articles

Summary

Hide ▲

More than 40,000 WordPress sites are exposed to CVE-2026-15826 in User Profile Builder, an authentication bypass that can let unauthenticated attackers obtain an administrator session on affected configurations.

Related Happenings

Forminator Forms arbitrary file upload flaw (CVE-2026-15748)

Vulnerability
H score18 First: 17.08.2026 21:22 Last: 17.08.2026 21:22 Sources 1

How related: "This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site compromise,"

About this happening: CVE-2026-15748 affects Forminator Forms for WordPress, exposing more than 600,000 active installations to unauthenticated arbitrary file upload and potential rem...

Timeline

  1. 17.08.2026 16:30 3 articles · 13d ago

    Wordfence receives report of CVE-2026-15826 in User Profile Builder

    Initial Disclosure

    Wordfence received a report about CVE-2026-15826 in the User Profile Builder plugin, an authentication bypass affecting versions up to and including 3.16.4 that can let unauthenticated attackers access an administrator account on more than 40,000 WordPress sites when the vulnerable configuration is present.

    Show sources
  2. 17.08.2026 16:30 1 articles · 13d ago

    Wordfence validates a type confusion flaw in the registration flow

    Technical Analysis Update

    Wordfence validated the flaw and found that a failed account-creation operation in User Profile Builder could be converted into an integer before the plugin checked for an error, causing the code to treat the result as user ID 1 and enabling automatic-login token generation for an administrator session.

    Show sources
  3. 17.08.2026 16:30 1 articles · 13d ago

    Cozmoslabs releases User Profile Builder 3.16.5 to fix the authentication bypass

    Mitigation Patch Update

    Cozmoslabs released User Profile Builder version 3.16.5 to address CVE-2026-15826, and affected site owners were told to update to version 3.16.5 or later.

    Show sources