User Profile Builder WordPress Plugin Authentication Bypass (Type Confusion Admin Takeover)
criticalZero-DayThe User Profile Builder plugin for WordPress (versions up to 3.16.4) contains a critical authentication bypass vulnerability caused by improper error handling during user registration. An unauthenticated attacker can exploit a type confusion flaw to obtain an autologin nonce bound to user ID 1, effectively logging in as the site's Administrator and achieving full site takeover.
Updated Aug 17, 2026 · CVSS 9.8