logo

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

ID: 25ad9039-f40c-5c1f-a50b-cbd08c254fe4

STIX ID: report--25ad9039-f40c-5c1f-a50b-cbd08c254fe4

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-08-17

Date Updated: 2026-08-17

...
...

A critical type-confusion vulnerability (CVE-2026-15826, CVSS 9.8) in the User Profile Builder WordPress plugin could let unauthenticated attackers obtain administrator sessions and fully compromise sites; over 40,000 sites were exposed, though exploitation requires the site to use user ID 1 and enable automatic login after registration. Cozmoslabs released version 3.16.5 to address the issue and site owners are advised to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.