ZeroHour

CVE-2026-76548

moderate

Unauthenticated Privilege Escalation in User Profile Builder WordPress Plugin

CVSS 3.1
8.2 high
EPSS
<1%p8
Published
()
Modified
AI analysis

The User Profile Builder WordPress plugin before 4.0.1 fails to properly restrict its front-end file upload feature, so requests from unauthenticated visitors are not correctly checked against the privileged-role capabilities they should have (CWE-287, improper authentication). An attacker triggers the flaw simply by sending requests to the plugin's front-end upload functionality on an affected site without logging in. This grants the attacker capabilities normally reserved for privileged users: listing the site's media library and modifying unpublished posts, pages, and media items belonging to other users, yielding a low-impact information disclosure with a high-impact integrity change, consistent with the 8.2 CVSS score (C:L/I:H/A:N). Any WordPress site running an affected version of the plugin, particularly where the front-end upload feature is reachable, is affected, and version 4.0.1 contains the fix. No public proof-of-concept is known, the flaw is not listed in CISA's KEV, and its EPSS of 0.2% (8th percentile) indicates a low likelihood of exploitation in the next 30 days.

What to do: Update User Profile Builder to version 4.0.1 or later. If you cannot update immediately, disable or restrict the plugin's front-end file upload capability, for example by limiting access to the upload endpoint via a WAF or firewall rule, until you can patch. After patching, review unpublished posts, pages, and the media library for unauthorized changes made by anonymous visitors.

Affected
User Profile Builder (WordPress plugin)all versions before 4.0.1 (fixed in 4.0.1)
Estimated exposure
moderatelikely on the order of thousands of sites (roughly 1,000-10,000); exact count unknown, as no active-install figure is provided in the source data — No active-install count was provided, so this range is an uncertain order-of-magnitude estimate based on the typically small-to-mid install bases of niche front-end user-profile plugins in the WordPress plugin directory.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.

Ecosystems
WordPress
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.