A critical vulnerability in the User Profile Builder plugin for WordPress has exposed over 40,000 sites to potential admin takeover. Identified as CVE-2026-15826, this flaw allows unauthenticated attackers to gain administrator access due to a type confusion error in the plugin's login flow. Affected versions include 3.16.4 and earlier. The flaw carries a CVSS score of 9.8, indicating high severity. Site owners are advised to update to version 3.16.5 or later to mitigate the risk.
User Profile Builder Flaw CVE-2026-15826 Exposes 40k Sites
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
User Profile Builder Flaw CVE-2026-15826 Exposes 40k Sites
www.infosecurity-magazine.com
-
Critical WordPress Plugin Flaw Lets Hackers Hijack Admin Accounts
cybersixt.com