User Profile Builder authentication bypass (CVE-2026-15826)
Vulnerability
Summary
Hide ▲
Show ▼
More than 40,000 WordPress sites are exposed to CVE-2026-15826 in User Profile Builder, an authentication bypass that can let unauthenticated attackers obtain an administrator session on affected configurations.
Related Happenings
Forminator Forms arbitrary file upload flaw (CVE-2026-15748)
Vulnerability
H score18
First: 17.08.2026 21:22
Last: 17.08.2026 21:22
Sources 1
How related:
"This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site compromise,"
About this happening:
CVE-2026-15748 affects Forminator Forms for WordPress, exposing more than 600,000 active installations to unauthenticated arbitrary file upload and potential rem...
Forminator Forms arbitrary file upload flaw (CVE-2026-15748)
VulnerabilityHow related: "This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site compromise,"
About this happening: CVE-2026-15748 affects Forminator Forms for WordPress, exposing more than 600,000 active installations to unauthenticated arbitrary file upload and potential rem...
Timeline
-
17.08.2026 16:30 3 articles · 13d ago
Wordfence receives report of CVE-2026-15826 in User Profile Builder
Initial DisclosureWordfence received a report about CVE-2026-15826 in the User Profile Builder plugin, an authentication bypass affecting versions up to and including 3.16.4 that can let unauthenticated attackers access an administrator account on more than 40,000 WordPress sites when the vulnerable configuration is present.
Show sources
- WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — www.infosecurity-magazine.com — 17.08.2026 16:30
- WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — www.infosecurity-magazine.com — 17.08.2026 16:30
- Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads — thehackernews.com — 17.08.2026 21:22
-
17.08.2026 16:30 1 articles · 13d ago
Wordfence validates a type confusion flaw in the registration flow
Technical Analysis UpdateWordfence validated the flaw and found that a failed account-creation operation in User Profile Builder could be converted into an integer before the plugin checked for an error, causing the code to treat the result as user ID 1 and enabling automatic-login token generation for an administrator session.
Show sources
- WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — www.infosecurity-magazine.com — 17.08.2026 16:30
-
17.08.2026 16:30 1 articles · 13d ago
Cozmoslabs releases User Profile Builder 3.16.5 to fix the authentication bypass
Mitigation Patch UpdateCozmoslabs released User Profile Builder version 3.16.5 to address CVE-2026-15826, and affected site owners were told to update to version 3.16.5 or later.
Show sources
- WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — www.infosecurity-magazine.com — 17.08.2026 16:30