DEV Community

Cover image for Critical Authentication Bypass Reported in User Profile Builder
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Critical Authentication Bypass Reported in User Profile Builder

Summary

Cozmoslabs patched a critical authentication bypass vulnerability (CVE-2026-15826) in the User Profile Builder WordPress plugin that allowed unauthenticated attackers to gain full administrative control.

Take Action:

If you run the User Profile Builder plugin on WordPress, update it to version 3.16.5 or later ASAP. If you can't update immediately, turn off the "Automatically Log In after Registration" setting in the plugin options, and check whether your admin account is user ID 1 and if possible switch to a different admin account.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)