A security vulnerability has been identified in the User Profile Builder plugin for WordPress.
This flaw affects all versions of the plugin up to and including 3.16.4. It allows unauthenticated third parties to bypass standard login protections to access your site’s primary administrator account.
If successfully exploited, this would give an attacker full administrative control of your website. They could modify site content, access sensitive private data, adjust critical site settings, or take other harmful actions without your knowledge or permission.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15826