WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
ID: 25ad9039-f40c-5c1f-a50b-cbd08c254fe4
STIX ID: report--25ad9039-f40c-5c1f-a50b-cbd08c254fe4
Feed Name: Infosecurity Magazine (News)
Threat Score
A critical type-confusion vulnerability (CVE-2026-15826, CVSS 9.8) in the User Profile Builder WordPress plugin could let unauthenticated attackers obtain administrator sessions and fully compromise sites; over 40,000 sites were exposed, though exploitation requires the site to use user ID 1 and enable automatic login after registration. Cozmoslabs released version 3.16.5 to address the issue and site owners are advised to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
