If your site uses the User Profile Builder plugin, check your settings today. A critical flaw can let an attacker log in as your site administrator without a password.

What happened

User Profile Builder, a plugin used to build custom registration forms and manage user profiles, has a critical authentication bypass. Wordfence says the flaw lets an unauthenticated attacker log in as the user with ID 1, which is typically the site’s original administrator account. That gives the attacker full control of the site.

The bug is only exploitable on sites that have the plugin’s Automatic Log In setting turned on, a feature that signs a user in right after they register. The flaw sits in how the plugin logs that user in: it doesn’t properly verify whose account it’s signing into, so an attacker can trick it into starting a session as the administrator instead.

Researcher Supakiad S. (m3ez) found and reported the flaw through the Wordfence Bug Bounty Program on July 14, 2026, earning a $975 bounty. Wordfence rated the issue 9.8 out of 10, tracked as CVE-2026-15826. Cozmoslabs, the plugin’s developer, acknowledged the report and shipped a fix the next day.

Who is affected

Every site running User Profile Builder version 3.16.4 or earlier with Automatic Log In enabled is vulnerable. The plugin has more than 40,000 active installations. Wordfence Premium, Care, and Response users received a firewall rule blocking exploit attempts on July 15, 2026. Sites on the free version of Wordfence did not get that protection until August 14, 2026, a full month later, so anyone running the free firewall was exposed the whole time.

What to do

Update User Profile Builder to version 3.16.5 or later right away. If you don’t use the Automatic Log In feature, turn it off in the plugin settings as an extra precaution until you’ve confirmed the update is installed.


End of article