A critical authentication bypass vulnerability, tracked as CVE-2026-15826, affects the WordPress plugin User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor in versions up to and including 3.16.4. The flaw carries a CVSS 9.8 rating and stems from a type confusion bug in the plugin’s autologin flow: a WP_Error returned by wp_insert_user() can be passed through absint() before error handling, coercing the value to integer 1. An unauthenticated attacker can exploit this by registering with a username between 61 and 70 characters, causing the plugin to generate an autologin nonce for user ID 1, which is commonly the site administrator.
Successful exploitation can result in full administrative takeover of affected WordPress sites, particularly where user ID 1 still belongs to an administrator account. Reports said roughly 40,000 sites were exposed. The issue was patched in 3.16.5, and defenders were urged to update immediately, review administrator accounts for unauthorized access, and verify whether the default administrator mapping to user ID 1 remains in place. Wordfence said firewall protections were released first to paid customers and later to free users.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-15826 was published, describing a critical unauthenticated authentication bypass in the User Profile Builder plugin with a CVSS 9.8 score.
Wordfence made firewall protection for CVE-2026-15826 available to free users, after previously providing it to paid tiers. The vulnerability was reported as affecting roughly 40,000 WordPress sites.
The vendor acknowledged the vulnerability report and released User Profile Builder version 3.16.5 to patch the authentication bypass flaw affecting versions up to 3.16.4.
Wordfence validated the report and confirmed a proof-of-concept exploit, then sent full disclosure details to the vendor through the Wordfence Vulnerability Management Portal. On the same day, Wordfence also distributed a firewall rule to Premium, Care, and Response customers.
Supakiad S. (m3ez) submitted a vulnerability report for the User Profile Builder WordPress plugin through the Wordfence Bug Bounty Program. The issue was later tracked as CVE-2026-15826.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcecvefeed.io
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.