Summary
Cozmoslabs patched a critical authentication bypass vulnerability (CVE-2026-15826) in the User Profile Builder WordPress plugin that allowed unauthenticated attackers to gain full administrative control.
Take Action:
If you run the User Profile Builder plugin on WordPress, update it to version 3.16.5 or later ASAP. If you can't update immediately, turn off the "Automatically Log In after Registration" setting in the plugin options, and check whether your admin account is user ID 1 and if possible switch to a different admin account.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)