The User Profile Builder WordPress plugin before 3.16.4...
High severity
Unreviewed
Published
Aug 1, 2026
to the GitHub Advisory Database
•
Updated Aug 5, 2026
Description
Published by the National Vulnerability Database
Aug 1, 2026
Published to the GitHub Advisory Database
Aug 1, 2026
Last updated
Aug 5, 2026
The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration.
References