• PoC PUBLIC

CVE-2026-15826: pre-auth authentication bypass in cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor

An unauthenticated attacker can obtain administrative access to the User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin, enabling full site takeover (CVE-2026-15826). Versions 3.x up to and including 3.16.4 are affected. No existing account or user interaction is required; a remote attacker can trigger the flaw via crafted registration input to gain an autologin token tied to the Administrator account.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.03904
CWE
CWE-704
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists and the bug allows direct administrative takeover without authentication, so remove or take the plugin offline until a vendor fix is released.

What is CVE-2026-15826?

An unauthenticated attacker can obtain administrative access to the User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin, enabling full site takeover (CVE-2026-15826). Versions 3.x up to and including 3.16.4 are affected. No existing account or user interaction is required; a remote attacker can trigger the flaw via crafted registration input to gain an autologin token tied to the Administrator account.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor are affected?

BRANCHAFFECTEDFIXED
3.x3.16.4 and earlier

Is CVE-2026-15826 being exploited?

Public exploit code is available.

How to fix CVE-2026-15826

  1. Deactivate or uninstall the User Profile Builder plugin immediately on internet-facing sites.
  2. If removal is not possible, block access to plugin endpoints and restrict registration and user-creation paths to trusted IPs.
  3. Monitor logs for unexpected logins and creation of autologin tokens, and rotate admin credentials and secrets if compromise is suspected.
  4. Follow the vendor's security guidance and apply updates from the vendor as soon as a patched release is published.

Frequently asked questions

Is CVE-2026-15826 being actively exploited?

Public exploit code is available for CVE-2026-15826.

Which User Profile Builder versions are affected by CVE-2026-15826?

Versions in the 3.x branch up to and including 3.16.4 are affected.

Is there a patch for CVE-2026-15826?

No fixed version is listed; the vendor has not published a patched release for the affected versions.

Does CVE-2026-15826 require authentication?

No, the vulnerability can be exploited by an unauthenticated remote attacker against the User Profile Builder plugin.

References