CVE-2026-15826Disclosure

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check — when a registration is submitted with a 61–70 character username, WordPress core rejects it with a WP_Error object, but absint() coerces that object to the integer 1 before the error check can short-circuit execution, causing the plugin to bind and return a transient-backed autologin nonce tied to user ID 1. This makes it possible for unauthenticated attackers to log in as the site's Administrator account (user ID 1), resulting in full administrative takeover of the site.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-704

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 7 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 14 signals
  • Disclosure: 6 classified signals
  • Peaked 5d ago at 5 mentions (2026-08-15); latest day: 1
  • 14 total mentions across 7 days

Deep dive

Activity timeline14 mentions / 7d
01345Mentions · 2026-08-14: 1Mentions · 2026-08-15: 5Mentions · 2026-08-16: 1Mentions · 2026-08-17: 2Mentions · 2026-08-18: 2Mentions · 2026-08-19: 2Mentions · 2026-08-25: 1Exploit Tool / Code · 2026-08-17: 1Active Exploitation · 2026-08-15: 1Active Exploitation · 2026-08-18: 1Patch / Workaround · 2026-08-15: 4Patch / Workaround · 2026-08-16: 1Patch / Workaround · 2026-08-17: 2Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-14: 1Technical Details · 2026-08-15: 5Technical Details · 2026-08-16: 1Technical Details · 2026-08-17: 2Technical Details · 2026-08-18: 2Technical Details · 2026-08-19: 2Technical Details · 2026-08-25: 108-1408-1508-1608-1708-1808-1908-25
Signal classification3 categories
Disclosure
642.9%
Patch
642.9%
Active Exploitation
214.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-141
Disclosure1
2026-08-155
Active Exploitation1Disclosure2Patch2
2026-08-161
Patch1
2026-08-172
Disclosure1Patch1
2026-08-182
Active Exploitation1Disclosure1
2026-08-192
Disclosure1Patch1
2026-08-251
Patch1
Full discourse14 posts
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: CVE-2026-15826 (CVSS 9.8) allows unauthenticated attackers to bypass authentication and take over WordPress administrator accounts. The flaw affects User Profile Builder ≤ 3.16.4, putting 40,000+ sites at risk. The issue is fixed in 3.16.5. Update immediately. #WordPress #CVE #CyberSecurity #WebSecurity #Infosec

    Post summary

    Critical vulnerability CVE-2026-15826 in WordPress User Profile Builder allows authentication bypass; fixed in version 3.16.5, so update immediately.

    33711467929.5K
    1.6K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-15826 - critical 🚨 User Profile Builder 3.16.4 - Unauthenticated Authentication Bypass > The User Profile Builder plugin for WordPress version 3.16.4 is vulnerable to an auth... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-15826 @pdnuclei #NucleiTemplate...

    Post summary

    The post announces CVE‑2026‑15826, a critical unauthenticated authentication bypass in WordPress User Profile Builder 3.16.4, and provides a link to a library entry for details.

    050116576
    1.3K followersView on X
  • Aikido Community Japan@AikidoCommJP
    Disclosure

    WordPressのフォームプラグイン、Forminator Formsに未認証RCE。 CVE-2026-15748。CVSS 9.8。 Forminatorは60万以上のサイトで使われている。 条件は、File UploadとSelectの両方を持つフォームが存在すること。 攻撃者はログイン不要。 細工したリクエストでPHPファイルをアップロードし、最終的にサイト上でコード実行まで到達できる。 根っこはかなり教科書的。 危険な拡張子をブロックしているが、判定が「完全一致」。 MIMEタイプのキーをパイプ区切りにすることでチェックをすり抜けられる。 さらにSelectフィールドを偽装すると、アップロード先の設定まで攻撃者側から操作できる。 つまり、 「危険な拡張子は弾いているから大丈夫」 だけでは防げなかった。 修正版は1.56.2。 Forminatorを使っているサイトは、まずバージョン確認と更新を。 同じ記事では、User Profile Builderの認証バイパス CVE-2026-15826(CVSS 9.8)も報告されている。 こちらはWP_Errorを確認する前にabsint()へ渡したことで整数1に丸められ、結果としてID=1の管理者としてログインできてしまう問題。 修正版は3.16.5。 WordPressは本体だけでなく、プラグイン側の更新確認も重要です。 #WordPress #Forminator #脆弱性 #RCE #AppSec #WebSecurity

    Post summary

    The post announces the discovery of a high‑severity, unauthenticated RCE vulnerability in the Forminator Forms plugin, details how it can be exploited, and confirms that a patch (1.56.2) is already available.

    010221.1K
    860 followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    WordPressプラグイン「User Profile Builder」に、未認証の攻撃者が管理者としてログインできる脆弱性CVE-2026-15826が見つかった。4万以上のサイトが影響を受け、Wordfenceは過去24時間に13件の実攻撃を遮断したという。 脆弱性は登録と自動ログイン処理に存在する。WordPress本体は60文字を超えるユーザー名を拒否してエラーを返すが、プラグインは61〜70文字のユーザー名を受け付ける。さらに、エラー確認前にPHPのabsint()を適用するため、エラーオブジェクトが数値1へ変換され、通常は最初の管理者アカウントに対応するユーザーID 1として処理される。 その結果、失敗した登録処理からユーザーID 1用の有効な自動ログインリンクが生成され、攻撃者はパスワードなしで管理者としてログインできる。影響するのは3.16.4以前で、「Automatically Log In after Registration」が有効なサイトに限られる。 修正版は3.16.5で、Wordfenceは公開前にファイアウォール保護を実装した。更新できない場合は自動ログイン設定を無効にすることで攻撃経路を遮断できるとしている。 https://securityonline.info/user-profile-builder-cve-2026-15826/

    Post summary

    CVE‑2026‑15826 allows unauthenticated attackers to log in as admin via a flaw in User Profile Builder’s registration logic; 13 attacks were blocked in 24 hours, and a patch is available.

    010301.9K
    15.0K followersView on X
  • iototsecnews@iototsecnews
    Patch

    WordPress User Profile Builder プラグインの脆弱性 CVE-2026-15826 が FIX:管理者権限奪取の恐れ https://iototsecnews.jp/2026/08/17/wordpress-plugin-flaw-exposes-40000-sites-to-admin-takeover/ WordPress User Profile Builder プラグインに存在する、認証回避の脆弱性 CVE-2026-15826 について解説する記事です。この問題はアカウント作成処理の型変換エラーに起因しており、未認証の第三者がサイトの管理者権限を奪取する恐れがあります。攻撃が成功した攻撃者により、コンテンツの改竄 / 管理者の不正追加 / 悪意あるプラグインの導入 / 機密情報の閲覧といった深刻な被害が引き起こされる可能性があります。運用への重大なリスクを避けるため、修正済みバージョンである 3.16.5 以降へと速やかに更新することが推奨されます。 #CVE202615826 #UserProfileBuilder #Vulnerability #WordPress

    Post summary

    The article announces a critical authentication bypass vulnerability in User Profile Builder, recommends updating to the patched 3.16.5+ release, and outlines the potential impact of successful exploitation.

    00110306
    510 followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-15826 (CVSS 9.8) in User Profile Builder affects 40,000+ WordPress sites. A type confusion bug in wppb_log_in_user() coerces a WP_Error object to integer 1 via absint(), granting unauthenticated admin takeover. #DFIR_Radar https://t.co/IWThbTlLd2

    Post summary

    The post announces CVE-2026-15826, a type confusion bug in WordPress User Profile Builder that allows unauthenticated admin takeover, affecting over 40,000 sites.

    10001151
    1.8K followersView on X
  • The CyberSec Guru@thecybersecguru
    Patch

    🚨 CRITICAL WORDPRESS SECURITY ALERT Two CVEs put vulnerable WordPress sites at serious risk: 🔴 CVE-2026-15748 — Forminator RCE 🔴 CVE-2026-15826 — User Profile Builder Auth Bypass ⚠️ CVSS 9.8 Critical One can lead to unauthenticated RCE. The other can enable admin takeover. Patch NOW 👇 https://thecybersecguru.com/news/cve-2026-15748-forminator-rce-cve-2026-15826-user-profile-builder/

    Post summary

    The post alerts on two critical WordPress plugin vulnerabilities, urging immediate patching and providing a link for further details.

    00010136
    1.2K followersView on X
  • サイトドック|Webセキュリティ解説 一ノ瀬あかり@sitedock_jp
    Disclosure

    4万サイトが使うWordPressプラグイン『User Profile Builder』に、未認証で管理者を乗っ取れる致命的な穴(CVE-2026-15826)。原因はPHPの型の取り違えという地味なバグでした。影響の確認方法と今すぐやるべき対処をまとめます。

    Post summary

    The post announces a critical vulnerability (CVE-2026‑15826) in WordPress User Profile Builder that allows unauthenticated attackers to take over the admin account via a PHP type‑confusion bug, but it does not provide PoC, exploit code, or patch details.

    1000046
    12 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    CVE-2026-15826 (CVSS 9.8) is a User Profile Builder vulnerability letting attackers log in as WordPress admin. Over 40,000 sites affected; update to 3.16.5 #CVE202615826 #WordPress #UserProfileBuilder #InfoSec https://securityonline.info/user-profile-builder-cve-2026-15826/

    Post summary

    A high‑severity WordPress User Profile Builder flaw (CVE‑2026‑15826) allows admin login and affects over 40,000 sites; users should update to version 3.16.5 to remediate.

    00100443
    12.7K followersView on X
  • Cert-IST@cert_ist
    Active Exploitation

    Plus de 40 000 sites WordPress ont été exposés à la CVE-2026-15826, une vulnérabilité critique dans le plugin User Profile Builder qui permet aux attaquants non authentifiés d'accéder au compte administrateur du site. https://tinyurl.com/2s3z7c7h

    Post summary

    The passage reports that more than 40,000 WordPress sites were exposed via CVE-2026-15826, a critical unauthenticated privilege‑escalation flaw in the User Profile Builder plugin.

    00000138
    959 followersView on X
  • SecureChap@SecureChap
    Patch

    CVE-2026-15748 Forminator Forms handle_file_upload rejects MIME types by literal key match. Supply a pipe variant plus a forged Select value and the check is skipped entirely. Default paths get an .htaccess via wp_handle_upload; custom File Upload Storage paths skip it because the file lands on the first unauthenticated request that never calls the helper. Spot it by grepping for custom upload_dir filters that write without the subsequent .htaccess step. Fixed in 1.56.2. CVE-2026-15826 User Profile Builder wppb_log_in_user runs the wp_insert_user result through absint before the is_wp_error test. A 61-character username forces the WP_Error branch; absint turns that into 1 and the caller logs in as admin. Spot it by finding any absint on an insert-user return that precedes the error check. Fixed in 3.16.5.

    Post summary

    Both CVE‑2026‑15748 and CVE‑2026‑15826 detail specific flaws in WordPress plugin handling—file upload bypass and authentication hijack—while noting that official fixes are already available in newer plugin versions.

    0000076
    164 followersView on X
  • ro0TCr4k@ro0TCr4k
    Patch

    🚨 Web3 teams: most project sites run WordPress. CVE-2026-15826 (CVSS 9.8) in User Profile Builder lets anyone register with a 61+ char username and land as admin. No auth required. Update to 3.16.5+ — check if you're exposed.

    Post summary

    The tweet alerts Web3 teams that WordPress sites using User Profile Builder are vulnerable to CVE-2026-15826, which allows privilege escalation via a long username, and advises updating to version 3.16.5+.

    0000093
    467 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    CyberSec Daily ✓ · 🌐 WordPress Security · August 15, 2026 🎯 Critical WordPress plugin flaw threatens more than 40,000 websites CVE-2026-15826 affects User Profile Builder versions up to and including 3.16.4. Under a specific configuration, an unauthenticated attacker may be able to access the site’s primary administrator account. The vulnerability carries a CVSS score of 9.8. WordPress administrators should upgrade to a corrected version and review administrator accounts and recent login activity. 🔗 Sources: Wordfence investigation / Wordfence vulnerability record / SecurityOnline report #WordPress #CVE202615826 #WebSecurity #AuthenticationBypass #PatchNow

    Post summary

    A critical authentication bypass flaw (CVE-2026-15826) in User Profile Builder threatens over 40,000 WordPress sites; administrators are urged to upgrade to the patched version to prevent unauthorized admin access.

    0000056
    58 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-15826 The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the w… https://www.cve.org/CVERecord?id=CVE-2026-15826

    Post summary

    The statement announces CVE‑2026‑15826, noting an authentication bypass via type confusion in User Profile Builder up to version 3.16.4, but offers no PoC, exploit, or patch details.

    000001.6K
    57.9K followersView on X

Explore more