๐Ÿ” CVE Alert

CVE-2026-15368

UNKNOWN 0.0

Profile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login After Registration

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration.

Vendor unknown
Product user profile builder
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown user profile builder

Be the first to know when new unknown vulnerabilities affecting unknown user profile builder are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / User Profile Builder
0 < 3.16.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/df1eb738-15bf-4f8b-aa06-e0a42f1e9c2e/

Credits

Jakub Herman WPScan