www.infosecurity-magazine.com 17 Aug 2026, 13:30 UTC

User Profile Builder Flaw CVE-2026-15826 Exposes 40k Sites

User Profile Builder Flaw CVE-2026-15826 Exposes 40k Sites
CyberSIXT Evidence Panel
Primary Source wordfence.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in the User Profile Builder plugin for WordPress has exposed over 40,000 sites to potential admin takeover. Identified as CVE-2026-15826, this flaw allows unauthenticated attackers to gain administrator access due to a type confusion error in the plugin's login flow. Affected versions include 3.16.4 and earlier. The flaw carries a CVSS score of 9.8, indicating high severity. Site owners are advised to update to version 3.16.5 or later to mitigate the risk.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline