CVE · Critical

CVE-2026-15826 — User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.16.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15826 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.16.5 Incorrect Type Conversion or Cast Critical 9.8 < 3.16.5 3.16.5 2026-08-14

CVE-2026-15826

The User Profile Builder plugin for WordPress has a security flaw that allows unauthorized users to bypass authentication and access the site's administrator account. This occurs when a user attempts to register with a username between 61 and 70 characters, which WordPress rejects due to a username length restriction. However, the plugin's handling of this rejection allows it to inadvertently create a login token for the administrator account, enabling an attacker to gain full control over the site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.