CVE-2026-15826

9.8

cozmoslabs · User Profile Builder

The User Profile Builder plugin for WordPress is vulnerable to an authentication bypass via type confusion, allowing unauthenticated attackers to log in as the site administrator.

Executive summary

A critical authentication bypass in the User Profile Builder WordPress plugin permits unauthenticated attackers to gain full administrative access.

Vulnerability

The plugin incorrectly handles return values from WordPress core registration functions, where a type confusion vulnerability allows an error object to be coerced into an integer. This flaw allows an unauthenticated attacker to generate a valid administrative session for user ID 1.

Business impact

This vulnerability provides an attacker with full administrative control over the affected WordPress site. Given the CVSS score of 9.8, this could lead to complete site compromise, including data theft, malicious code injection, and total loss of site control.

Remediation

Immediate Action: Update the User Profile Builder plugin to version 3.16.5 or later immediately.

Proactive Monitoring: Review user registration logs for unusual activity and monitor for the creation of unauthorized administrative accounts.

Compensating Controls: Utilize a Web Application Firewall to block suspicious registration requests that match the characteristics of this attack vector.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This is a critical vulnerability that directly impacts the security posture of any WordPress site using this plugin. Administrators must apply the update to version 3.16.5 as a priority to eliminate the risk of unauthorized administrative access.

More cozmoslabs CVEs