THREAT OPS › Threat News › 40,000 WordPress Sites affected by Authentication Bypass Vulnerability in User Profile Builder WordPress Plugin
40,000 WordPress Sites affected by Authentication Bypass Vulnerability in User Profile Builder WordPress Plugin
<p>On July 14th, 2026, we received a submission for an Authentication Bypass vulnerability in <a href="https://wordpress.org/plugins/profile-builder/" rel="noopener" target="_blank">User Profile Builder</a>, a WordPress plugin with more than 40,000 active installations. This vulnerability makes it possible for unauthenticated attackers to log in as the user with ID 1, which is typically the site a
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- 2be53568b04545bf9e036c375a3d44d9md5
- CVE-2026-15826cve
- https://wordpress.org/plugins/profile-builder/url
- https://www.cve.org/CVERecord?id=CVE-2026-15826url
- www.gravatar.comdomain