Skip to content
September 28, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • CVE-2026-15826: User Profile Builder Bug Under Active Attack, Grants Full Admin Takeover (CVSS 9.8)
  • Vulnerability Report

CVE-2026-15826: User Profile Builder Bug Under Active Attack, Grants Full Admin Takeover (CVSS 9.8)

Do Son August 15, 2026 3 minutes read
0
User Profile Builder vulnerability CVE-2026-15826 WordPress authentication bypass illustration
Add Daily CyberSecurity as a preferred source on Google

TL;DR: A critical User Profile Builder vulnerability, carrying a maximum CVSS score of 9.8 and tracked as CVE-2026-15826, now threatens more than 40,000 WordPress sites. It lets unauthenticated attackers log straight in as a site’s administrator. Wordfence’s firewall has already blocked 13 real attacks against the bug in the past 24 hours.

Running Infra, AppSec, and SOC teams? Tag WordPress alerts by team automatically.

Try Team free for 14 days →

Why It Matters

User Profile Builder powers custom registration, login, and profile forms on more than 40,000 WordPress sites. This bug puts full administrative control up for grabs. Once attackers reach the dashboard, they can create rogue admin accounts, install a backdoor plugin, or siphon customer data. Attackers could also plant persistent backdoors that survive a plugin update. Similarly, they can rewrite site content or redirect visitors to malicious pages. The attack requires no valid credentials, so any site running the plugin’s Automatically Log In setting stays at risk.

Security researcher Supakiad S., known online as m3ez, found and privately reported the flaw through Wordfence’s Bug Bounty Program. As a result, Wordfence built firewall protection before the vulnerability became public knowledge.

How the Attack Works

This User Profile Builder vulnerability sits inside the plugin’s registration and autologin flow. WordPress core rejects any username longer than 60 characters and returns an error object instead. A 61-to-70 character username passes the plugin’s own checks but fails WordPress core’s limit, triggering the flaw. However, the plugin’s own function calls PHP’s absint() on that error object before checking whether an error occurred. That call converts the error into the number 1, which happens to match the site’s original administrator ID.

As a result, the plugin treats the failed registration as a successful login for user ID 1. It then generates a valid autologin link tied to that same ID. Anyone who follows the link signs in as the administrator, without supplying a password.

Affected Versions

The vulnerability affects User Profile Builder through version 3.16.4. WordPress.org’s plugin listing shows more than 40,000 active installs. Version 3.16.5 contains the fix. The plugin remains widely used by membership sites, online communities, and course platforms. Sites only face risk when the plugin’s Automatically Log In after Registration setting stays enabled, Wordfence’s advisory notes.

Patch and Mitigation Steps

Site owners should update User Profile Builder to version 3.16.5 right away. This single update closes the User Profile Builder vulnerability completely. Administrators who cannot update immediately should turn off the Automatically Log In after Registration setting instead. That step alone blocks the attack path, even on outdated installs. Site owners should also review admin accounts for any unfamiliar logins created before the patch. Logging tools can help confirm whether an attacker already exploited the bug.

Wordfence’s advisory urges affected users to apply the patched release “as soon as possible.”

Related coverage

  • Critical RCE Flaws Found in Flowise AI Platform, Allowing Remote Code Execution
  • Urgent Veeam Update: Critical RCE CVE-2025-23121 (CVSS 9.9) & Two Other Flaws Threaten Backup Servers
  • EKS Security Alert: Overprivileged Containers Exposing AWS Credentials via Unencrypted API
  • GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public
  • Critical-Severity XSS Flaws Uncovered in Siemens SIMATIC S7 Web Servers
  • CVE-2026-0622: Hardcoded Secret Exposes Open5GS 5G Core Networks
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Admin Takeover Authentication Bypass CVE-2026-15826 User Profile Builder WordPress Plugin Vulnerability wordpress security

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-101894CVSS 9.1
    The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101891CVSS 9.3
    An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker...
    📅 Updated: Sep 28, 2026
  • CVE-2026-86102CVSS 9.3
    An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access...
    📅 Updated: Sep 28, 2026
  • CVE-2026-100721CVSS 9.5
    vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101081CVSS 9.4
    A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the...
    📅 Updated: Sep 28, 2026
  • CVE-2026-100684CVSS 9.2
    Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate,...
    📅 Updated: Sep 28, 2026
  • CVE-2026-63374CVSS 9.3
    AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101075CVSS 10.0
    A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of...
    📅 Updated: Sep 28, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.