A security vulnerability exists in the User Profile Builder plugin for WordPress, affecting all versions of the plugin up to and including version 3.16.4. This flaw lets unapproved users who are not logged into your site bypass standard login protections to access your site’s main administrator account, which grants them full control over all your website’s content, settings, and user data.
The flaw is triggered when a person attempts to register for your site using a username between 61 and 70 characters long. When this happens, a bug in the plugin’s login function mishandles an error returned by WordPress core, allowing the attacker to generate a valid, password-free login link for the default administrator account on your site.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15826