CVE-2026-15826 (matched: wordpress)

  • Monday, 17th August, 2026
  • 10:05am

A security vulnerability has been identified in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. The flaw stems from a coding error in how the plugin processes user registration submissions. When a username between 61 and 70 characters is entered, WordPress core rejects the registration with an error message, but the plugin's code incorrectly converts that error into a valid user ID tied to the site's primary administrator account, and generates a one-time login token for that account. Attackers who do not have any existing login access to your site can exploit this flaw to log in as the main administrator, giving them full control over your entire WordPress website, including all content, settings, and user data.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15826

« Back