CVE-2026-15826 (matched: wordpress)

  • Saturday, 15th August, 2026
  • 16:05pm

A security flaw has been found in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. The issue is triggered when someone submits a user registration with a username between 61 and 70 characters long, due to a coding error in how the plugin processes these requests.

This error allows unauthenticated attackers to bypass standard login security to access your site’s main administrator account. Gaining administrator access gives an attacker full control of your website, including the ability to modify your site’s content, access private information stored on the site, or take over the site entirely.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15826

« Back