THREATOPS
THREAT OPSThreat News › 40,000 WordPress Sites affected by Authentication Bypass Vulnerability in User Profile Builder WordPress Plugin

40,000 WordPress Sites affected by Authentication Bypass Vulnerability in User Profile Builder WordPress Plugin

medwordfencePublished 2026-08-14

<p>On July 14th, 2026, we received a submission for an Authentication Bypass vulnerability in <a href="https://wordpress.org/plugins/profile-builder/" rel="noopener" target="_blank">User Profile Builder</a>, a WordPress plugin with more than 40,000 active installations. This vulnerability makes it possible for unauthenticated attackers to log in as the user with ID 1, which is typically the site a

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.wordfence.com/blog/2026/08/40000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-user-profile-builder-wordpress-plugin/