ZeroHour
Product

User Profile Builder

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Wordfence disclosed CVE-2026-15748, a critical unauthenticated file upload flaw enabling RCE in the Forminator Forms WordPress plugin, patched in version 1.56.2.

Wordfence reported CVE-2026-15748 (CVSS 9.8) in Forminator Forms, a WordPress plugin with over 600,000 active installations, allowing unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution. The flaw stems from insufficient file type validation in the handle_file_upload() function, and exploitation requires a form containing both a File Upload field and a Select field, plus a custom upload storage root lacking .htaccess PHP protection. All versions up to and including 1.56.1 are affected; version 1.56.2 released July 31, 2026 fixes the issue. Wordfence also disclosed CVE-2026-15826 (CVSS 9.8), an authentication bypass in User Profile Builder (40,000+ installs) letting unauthenticated attackers log in as administrator, fixed in version 3.16.5 on July 16, 2026.

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical unauthenticated flaw in the User Profile Builder WordPress plugin exposed roughly 40,000 sites to administrator account takeover.

Infosecurity Magazine reports a critical flaw in the User Profile Builder WordPress plugin that let unauthenticated attackers access administrator accounts. Approximately 40,000 sites were exposed to full admin takeover as a result. The report did not specify a CVE identifier or state whether exploitation was observed in the wild.

Infosecurity Magazine · 29d agoVulnerability

Related CVEs

  • Unauthenticated RCE via Arbitrary File Upload in Forminator Forms WordPress Plugin
    Forminator Forms, a widely used WordPress form-builder plugin, is vulnerable to an unauthenticated arbitrary file upload (CWE-434) in its handle_file_upload function in all versions up to and including 1.56.1. The weakness stems from insufficient file type validation: the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, while the public form-submission handler trusts upload field configuration that an attacker controls by forging a Select field value in a submitted form. An unauthenticated attacker can therefore upload files that may be executable, such as PHP scripts, achieving remote code execution with high impact to confidentiality, integrity, and availability (CVSS 3.1 score 9.8). Any WordPress site running Forminator Forms 1.56.1 or earlier, particularly those with publicly reachable forms, is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently assigns a 4.6% probability of exploitation within 30 days (91st percentile).
    · WPMU DEV Forminator Forms (WordPress plugin) All versions up to and including 1.56.1 (<= 1.56.1)large
  • Unauthenticated Admin Login Bypass in WordPress User Profile Builder Plugin (≤3.16.4)
    CVE-2026-15826 is an unauthenticated authentication bypass caused by type confusion (CWE-704) in the User Profile Builder plugin for WordPress in all versions up to and including 3.16.4. The plugin's wppb_log_in_user() function calls absint() on the return value of wp_insert_user() before checking is_wp_error(); when a registration is submitted with a 61–70 character username, WordPress core returns a WP_Error object, but absint() coerces that object to the integer 1, so the plugin issues an autologin nonce bound to user ID 1 that the attacker can redeem to log in. As a result, an unauthenticated attacker can obtain a session as the site's Administrator account (user ID 1), achieving full administrative takeover of the site. Any WordPress site running the plugin at version 3.16.4 or earlier, with the plugin's registration/autologin flow reachable and user ID 1 holding an Administrator role, is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known and the flaw is not in CISA KEV, though EPSS of 3.9% (90th percentile) suggests a moderate likelihood of exploitation within 30 days.
    · Cozmoslabs User Profile Builder (Profile Builder) plugin for WordPress All versions up to and including 3.16.4large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.