CVE-2026-76548
moderateUnauthenticated Privilege Escalation in User Profile Builder WordPress Plugin
The User Profile Builder WordPress plugin before 4.0.1 fails to properly restrict its front-end file upload feature, so requests from unauthenticated visitors are not correctly checked against the privileged-role capabilities they should have (CWE-287, improper authentication). An attacker triggers the flaw simply by sending requests to the plugin's front-end upload functionality on an affected site without logging in. This grants the attacker capabilities normally reserved for privileged users: listing the site's media library and modifying unpublished posts, pages, and media items belonging to other users, yielding a low-impact information disclosure with a high-impact integrity change, consistent with the 8.2 CVSS score (C:L/I:H/A:N). Any WordPress site running an affected version of the plugin, particularly where the front-end upload feature is reachable, is affected, and version 4.0.1 contains the fix. No public proof-of-concept is known, the flaw is not listed in CISA's KEV, and its EPSS of 0.2% (8th percentile) indicates a low likelihood of exploitation in the next 30 days.
What to do: Update User Profile Builder to version 4.0.1 or later. If you cannot update immediately, disable or restrict the plugin's front-end file upload capability, for example by limiting access to the upload endpoint via a WAF or firewall rule, until you can patch. After patching, review unpublished posts, pages, and the media library for unauthorized changes made by anonymous visitors.
| User Profile Builder (WordPress plugin) | all versions before 4.0.1 (fixed in 4.0.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.
- Ecosystems
- WordPress
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.