A security vulnerability has been identified in the User Profile Builder plugin for WordPress, a common tool used to let visitors create accounts and manage their profiles on WordPress websites. The flaw impacts all versions of the plugin up to and including version 3.16.4.
This vulnerability allows anyone who visits your site to log in as your main administrator account, even without any valid login credentials. An attacker with administrator access has full control over your entire website: they can edit or delete your content, access sensitive customer or business data, change your site’s settings, and take over all administrative functions. The exploit is triggered when a visitor submits a user registration request with a username that is between 61 and 70 characters long.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15826