A security flaw exists in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. The bug is triggered when a new user registration is submitted with a username that is between 61 and 70 characters long.
Due to a coding error in the plugin, attackers can exploit this issue to generate a valid login link for the site’s main Administrator account. This allows unauthenticated users to gain full administrative control of the site without a password, letting them alter site content, access private information, or make other unauthorized changes.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15826