A security vulnerability exists in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. This flaw allows people who do not have a valid account on your site to bypass normal login security measures.
If attackers exploit this vulnerability, they can log in as your site's main Administrator account, giving them full administrative control of your website. With this level of access, bad actors could alter your site's content, steal private data, or take other harmful actions that impact your site and visitors.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15826