/Vulnerability Library

User Profile Builder 3.16.4 - Unauthenticated Authentication Bypass

CVE-2026-15826
Verified

Description

The User Profile Builder plugin for WordPress version 3.16.4 is vulnerable to an authentication bypass via type confusion. Profile Builder's automatic-login-after-registration handler passes the return value of wp_insert_user() through absint() before testing it with is_wp_error(), so the error check runs against the already-coerced integer. A registration submitted with a 61-70 character username passes the plugin's own validation but is rejected by WordPress core, because the user_login column is VARCHAR(60), and wp_insert_user() returns a WP_Error object. absint() coerces that object to the integer 1, is_wp_error(1) is false, and the plugin binds a transient-backed autologin nonce to user ID 1. Consuming that nonce calls wp_set_auth_cookie(1) and logs the unauthenticated attacker in as the site's Administrator.

Severity

Critical

CVSS Score

9.8

Exploit Probability

4%

Affected Product

profile-builder

Published Date

August 18, 2026

Template Author

theamanrawat

CVE-2026-15826.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-15826
CWE ID:
cwe-704

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/9f606fba-f779-42ea-a160-6c3b20dc5e79https://plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/front-end/class-formbuilder.php#L262https://plugins.trac.wordpress.org/browser/profile-builder/tags/3.16.4/features/functions.php#L1481https://plugins.trac.wordpress.org/changeset/3609855/profile-builderhttps://github.com/HORKimhab/CVE-2026-15826-CVE-2026-15748https://nvd.nist.gov/vuln/detail/CVE-2026-15826

Remediation Steps

Update User Profile Builder to 3.16.5 or later, which performs the is_wp_error() check before coercing the wp_insert_user() return value with absint() and additionally enforces the 60-character username limit server-side.