๐Ÿ” CVE Alert

CVE-2026-82607

HIGH 7.3

Cozmoslabs Profile Builder Plugin Avatar Simple Upload AJAX admin-ajax.php wppb_ajax_simple_avatar unrestricted upload

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 3.16.2 is sufficient to resolve this issue. It is suggested to upgrade the affected component.

CWE CWE-434 CWE-284
Vendor cozmoslabs
Product profile builder plugin
Published Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for cozmoslabs profile builder plugin

Be the first to know when new high vulnerabilities affecting cozmoslabs profile builder plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Cozmoslabs / Profile Builder Plugin
3.16.0 3.16.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/397108 vuldb.com: https://vuldb.com/vuln/397108/cti vuldb.com: https://vuldb.com/cve/CVE-2026-82607 vuldb.com: https://vuldb.com/submit/892841 ciphersecuritylabs.com: https://ciphersecuritylabs.com/research/articles/when-the-browser-is-the-only-bouncer-unauthenticated-media-upload-in-profile-builder cozmoslabs.com: https://www.cozmoslabs.com/docs/profile-builder/free-changelog/

Credits

๐Ÿ” ciphersecuritylabs (VulDB User)