CVE-2026-76547
Profile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/Export
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is present in the User Profile Builder WordPress plugin before 4.0.1 itself, so further impact requires a suitable gadget from another installed User Profile Builder WordPress plugin before 4.0.1 or .
| Vendor | unknown |
| Product | user profile builder |
| Published | Aug 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown user profile builder
Be the first to know when new unknown vulnerabilities affecting unknown user profile builder are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / User Profile Builder
3.3.4 < 4.0.1
References
Credits
Vivien LEBAS WPScan