securityonline.info 8/15/2026, 6:26:14 AM · external

Critical WordPress Plugin Flaw Lets Hackers Hijack Admin Accounts

Critical WordPress Plugin Flaw Lets Hackers Hijack Admin Accounts
CyberSIXT Evidence Panel
Primary Source wordfence.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in the User Profile Builder plugin for WordPress, tracked as CVE-2026-15826, poses a severe risk to over 40,000 sites by allowing unauthenticated attackers to log in as administrators. This security flaw has a maximum CVSS score of 9.8 and allows attackers to create rogue admin accounts or install backdoors. Discovered by researcher Supakiad S. through Wordfence’s Bug Bounty Program, this vulnerability occurs due to improper checks in the registration and autologin processes.

Affected versions include all prior to 3.16.4, with version 3.16.5 providing a fix. Users are urged to update immediately or disable the Automatically Log In feature to mitigate risks.

View Primary Source Via securityonline.info

Article by CyberSIXT