A critical vulnerability in the User Profile Builder plugin for WordPress, tracked as CVE-2026-15826, poses a severe risk to over 40,000 sites by allowing unauthenticated attackers to log in as administrators. This security flaw has a maximum CVSS score of 9.8 and allows attackers to create rogue admin accounts or install backdoors. Discovered by researcher Supakiad S. through Wordfence’s Bug Bounty Program, this vulnerability occurs due to improper checks in the registration and autologin processes.
Affected versions include all prior to 3.16.4, with version 3.16.5 providing a fix. Users are urged to update immediately or disable the Automatically Log In feature to mitigate risks.