DIRAS TAKE
Urgent: public exploit code exists and the bug allows direct administrative takeover without authentication, so remove or take the plugin offline until a vendor fix is released.
What is CVE-2026-15826?
An unauthenticated attacker can obtain administrative access to the User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin, enabling full site takeover (CVE-2026-15826). Versions 3.x up to and including 3.16.4 are affected. No existing account or user interaction is required; a remote attacker can trigger the flaw via crafted registration input to gain an autologin token tied to the Administrator account.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 3.x | 3.16.4 and earlier |
Is CVE-2026-15826 being exploited?
Public exploit code is available.
How to fix CVE-2026-15826
- Deactivate or uninstall the User Profile Builder plugin immediately on internet-facing sites.
- If removal is not possible, block access to plugin endpoints and restrict registration and user-creation paths to trusted IPs.
- Monitor logs for unexpected logins and creation of autologin tokens, and rotate admin credentials and secrets if compromise is suspected.
- Follow the vendor's security guidance and apply updates from the vendor as soon as a patched release is published.
Frequently asked questions
Is CVE-2026-15826 being actively exploited?
Public exploit code is available for CVE-2026-15826.
Which User Profile Builder versions are affected by CVE-2026-15826?
Versions in the 3.x branch up to and including 3.16.4 are affected.
Is there a patch for CVE-2026-15826?
No fixed version is listed; the vendor has not published a patched release for the affected versions.
Does CVE-2026-15826 require authentication?
No, the vulnerability can be exploited by an unauthenticated remote attacker against the User Profile Builder plugin.
References
- nvd.nist.gov/vuln/detail/CVE-2026-15826
- cve.org/CVERecord?id=CVE-2026-15826
- wordfence.com/threat-intel/vulnerabilities/id/9f606fba-f779-42ea-a160-6c3b20dc5e79?source=cve
- plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/default-fields/username/username.php#L28
- plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/default-fields/username/username.php#L49
- plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/class-formbuilder.php#L742
- plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/class-formbuilder.php#L364
- plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/class-formbuilder.php#L262
- plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/features/functions.php#L1481
- plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/class-formbuilder.php#L945
- plugins.trac.wordpress.org/changeset/3609855/profile-builder
- All cozmoslabs CVEs on CVE Radar
- CVEs published in September 2026