www.infosecurity-magazine.com 8/17/2026, 1:41:30 PM · external

User Profile Builder Flaw CVE-2026-15826 Exposes 40k Sites

User Profile Builder Flaw CVE-2026-15826 Exposes 40k Sites
Developing story vulnerability 2 articles tracked
Critical WordPress User Profile Builder flaw (CVE-2026-15826) exposes 40,000 sites
CyberSIXT Evidence Panel
Primary Source wordfence.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in the User Profile Builder plugin for WordPress has exposed over 40,000 sites to potential admin takeover. Identified as CVE-2026-15826, this flaw allows unauthenticated attackers to gain administrator access due to a type confusion error in the plugin's login flow. Affected versions include 3.16.4 and earlier. The flaw carries a CVSS score of 9.8, indicating high severity. Site owners are advised to update to version 3.16.5 or later to mitigate the risk.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline