CVE-2026-7647Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter within the wppb_request_users_pins_action_callback() AJAX handler, which lacked any nonce verification, type checking, or input validation before deserialization. Because the handler was registered with both wp_ajax_ and wp_ajax_nopriv_ hooks, it was reachable by completely unauthenticated users. This makes it possible for unauthenticated attackers to inject arbitrary PHP objects into application memory.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 5 mentions (2026-05-02); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-05-02: 5Mentions · 2026-05-15: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-02: 5Technical Details · 2026-05-15: 105-0205-15
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-025
Disclosure5
2026-05-151
Patch1
Full discourse6 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🧨 CVE-2026-7647: Profile Builder Pro for WordPress is vulnerable to unauthenticated PHP object injection via attacker-controlled args in the AJAX handler. A simple deserialization bug can become a serious compromise path. #WordPress #PHP #Deserialization #CVE #AppSec https://nvd.nist.gov/vuln/detail/CVE-2026-7647

    Post summary

    The post announces the new vulnerability CVE‑2026‑7647 in Profile Builder Pro for WordPress, describing a PHP object injection flaw that could lead to serious compromise.

    1002047
    1.7K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-7647 The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including … CVSS 8.1 Full analysis → https://sec.kaitan.id/cves/CVE-2026-7647 #WordPress #CyberSecurity #InfoSec

    Post summary

    The post discloses CVE-2026-7647 affecting WordPress Profile Builder Pro, describing a PHP Object Injection vulnerability with a CVSS 8.1 score. No exploit, patch, or active exploitation details are provided.

    0001055
    458 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A critical vulnerability (CVE-2026-7647) affects the Profile Builder Pro WordPress plugin, allowing unauthenticated attackers to inject PHP objects. SMBs using this plugin should update immediately to reduce exposure. #Cybersecurity

    Post summary

    CVE-2026-7647 is a critical unauthenticated PHP object injection in the Profile Builder Pro WordPress plugin; users are urged to update the plugin immediately to mitigate the vulnerability.

    0000056
    80 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7647 The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_uns… https://www.cve.org/CVERecord?id=CVE-2026-7647 ----- Traducción: CVE-2026-7647 El … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑7647, identifying PHP Object Injection in Profile Builder Pro up to version 3.14.5, without mentioning PoC, exploit tools, active exploitation, or patches.

    0000034
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7647 The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_uns… https://www.cve.org/CVERecord?id=CVE-2026-7647

    Post summary

    The post announces that the Profile Builder Pro WordPress plugin suffers from PHP Object Injection up to version 3.14.5, providing basic technical details but no PoC, exploit, or patch information.

    00000176
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7647 PHP Object Injection in Profile Builder Pro Plugin for WordPress Up to 3.14.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7647

    Post summary

    The CVE is announced as a PHP Object Injection flaw affecting Profile Builder Pro Plugin for WordPress up to version 3.14.5, with no PoC, exploit, or patch details provided.

    0000051
    4.0K followersView on X

Explore more