CVE

CVE-2026-15368 — User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.16.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15368 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.16.4 Improper Privilege Management Unknown < 3.16.4 3.16.4 2026-08-01

CVE-2026-15368

A vulnerability in User Profile Builder WordPress plugin versions prior to 3.16.4 enables unauthorized access by permitting an attacker to hijack an existing user's session, potentially allowing them to assume administrative privileges if the targeted account has such permissions. This occurs due to an incorrect association of automatic login functionality with newly created accounts. Affected sites may be vulnerable if they utilize a configuration that diverges from default settings.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.