CVE-2026-15826 (matched: wordpress)

  • Monday, 17th August, 2026
  • 04:04am

A security vulnerability exists in the WordPress User Profile Builder plugin, affecting all versions up to and including 3.16.4. The flaw is triggered when someone submits a site registration with a username that is 61 to 70 characters long, and it allows unauthenticated, unauthorized attackers to bypass normal login security to access your site’s main administrator account.

Exploiting this vulnerability results in full administrative takeover of the affected website, giving an attacker complete control over all site operations and settings.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15826

« Back