WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

More than 40,000 WordPress sites have been exposed to an authentication bypass flaw in the User Profile Builder plugin that can let unauthenticated attackers access the site’s administrator account. The vulnerability, tracked as CVE-2026-15826 and given a critical CVSS rating of 9.8, affects User Profile Builder versions up to and including 3.16.4.

Source: Infosecurity Magazine – Information Security & IT Security

 


Date:

Categorie(s):