A security flaw tracked as CVE-2026-15826 has been identified in the User Profile Builder plugin for WordPress, impacting all versions up to and including 3.16.4. The vulnerability stems from a bug in the plugin's user login handling code that is triggered when a visitor submits a site registration attempt with a username between 61 and 70 characters long. This issue allows people who do not have an account or valid login credentials for your site to bypass standard authentication checks, and log in directly as your site's primary administrator account. If an attacker exploits this flaw, they will gain full administrative control of your website, with the ability to edit your site's content, access private data, and modify any of your site's settings or configurations.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15826