CVE-2026-15826 is a critical authentication bypass vulnerability in the User Profile Builder plugin for WordPress affecting versions up to and including 3.16.4. The flaw is caused by type confusion in the plugin's registration auto-login flow. In the vulnerable wppb_log_in_user() function, the return value of wp_insert_user() is passed to absint() before the code verifies whether the result is a WP_Error via is_wp_error(). When a registration is submitted with a username length that passes the plugin's frontend validation but is rejected by WordPress core, wp_insert_user() returns a WP_Error object. Because absint() coerces that object to the integer 1 before error handling occurs, execution continues as though a valid user ID had been returned. The plugin then binds and returns a transient-backed autologin nonce associated with user ID 1, which is typically the original administrator account. An unauthenticated attacker can abuse this logic to obtain an administrator session and take control of the site.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains two separate security artifacts. The first, CVE-2026-15748-scanner.py, is a Python multi-target scanner for WordPress Forminator that performs passive version detection by requesting common plugin files under /wp-content/plugins/forminator/ and classifies versions <= 1.56.1 as vulnerable. It is a scanner/detection utility rather than an exploit. The second, and primary exploit content, is under CVE-2026-15826-fankh/. This is a standalone Python PoC plus a self-contained Docker lab. The PoC targets the WordPress User Profile Builder plugin authentication bypass (CVE-2026-15826) affecting versions up to 3.16.4. Its logic first fingerprints WordPress using endpoints such as /wp-login.php, /wp-json/wp/v2/, and /xmlrpc.php, then looks for plugin/registration indicators on the homepage and common registration paths. The active validation path uses a crafted registration condition based on a 61-70 character username to trigger the type-confusion bug described in the README. The intended result is issuance of an autologin nonce tied to administrator user ID 1, which can then be redeemed to establish an authenticated admin session. Repository structure for CVE-2026-15826 includes README documentation in English and Korean, poc.py as the main exploit/detection script, docker-compose.yml to launch vulnerable and patched Flask demo apps, and run-tests scripts for Linux/macOS and PowerShell. The vulnerable-app/app.py file is an intentionally vulnerable educational simulation exposing /register, /autologin, /profile, and /users; it demonstrates the bug by coercing a WP_Error-like object to integer 1 before checking for errors, thereby granting admin-bound nonce issuance. The patched-app/app.py file shows the corrected logic by validating types before nonce generation. Overall, this repository is best characterized as an educational exploit PoC plus lab environment for authentication bypass/admin takeover, alongside an unrelated WordPress plugin version scanner for another CVE.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical pre-authentication authentication bypass and administrator takeover vulnerability in the WordPress User Profile Builder plugin caused by PHP type confusion and improper WP_Error handling in the auto-login registration flow.
Critical authentication bypass vulnerability in the User Profile Builder WordPress plugin that can let an unauthenticated attacker log in as user ID 1, typically the site administrator, leading to full administrative takeover when Automatically Log In is enabled.
Unknown
A critical authentication bypass vulnerability in the User Profile Builder WordPress plugin that can let unauthenticated attackers log in as the administrator account with user ID 1 and fully take over the site under certain configurations.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.