Critical Authentication Bypass Vulnerability Discovered in User Profile Builder Plugin for WordPress

Date:

On July 14, 2026, a severe Authentication Bypass vulnerability was identified in User Profile Builder, a widely-used WordPress plugin boasting over 40,000 active installations. This vulnerability allows unauthenticated users to log in as the user with ID 1, a typical designation for the site administrator, effectively granting them full control over the website. It is important to note that this issue is exploitable only in instances where the plugin’s Automatically Log In feature is enabled.

The discovery of this vulnerability is credited to Supakiad S. (m3ez), who responsibly reported it through the Wordfence Bug Bounty Program. As a result of this significant find, the researcher was rewarded with a bounty of $975.00. Wordfence is committed to enhancing WordPress security through a layered defense strategy, investing in advanced vulnerability research and collaborating with skilled researchers through its Bug Bounty Program.

Immediate Mitigation Steps

To safeguard users, Wordfence Premium, Wordfence Care, and Wordfence Response subscribers received a firewall rule on July 15, 2026, designed to protect against potential exploits related to this vulnerability. The same protective measure is set to be extended to users of the free version of Wordfence, with deployment scheduled for August 14, 2026.

On July 15, Wordfence provided detailed disclosure information to the Cozmoslabs team via its Vulnerability Management Portal. The developer acknowledged the findings on July 16 and promptly released the patched version, 3.16.5, on the same day. Wordfence commends the Cozmoslabs team for their quick and effective response in addressing this issue.

Details of the Vulnerability

The User Profile Builder plugin versions up to and including 3.16.4 are susceptible to a critical Authentication Bypass vulnerability caused by a type confusion flaw within the plugin’s authentication process. Specifically, the issue arises when the wppb_log_in_user() function improperly calls absint() on return values of wp_insert_user() before verifying for errors. When usernames between 61 and 70 characters are submitted, the WordPress core generates a WP_Error object, but the absint() function coerces this into the integer 1, effectively bypassing the error check and linking the attacker to an autologin nonce associated with the administrator account.

This flaw has significant implications as it permits an attacker to register with an appropriately long username and gain instantaneous access to the site’s administrator account (user ID 1), resulting in a complete site takeover.

Potential Consequences and Recommendations

Once an attacker successfully authenticates as an administrator, they can create additional administrator accounts, install malicious plugins or themes containing backdoors, alter site content, or extract confidential information. This vulnerability poses a profound risk to sites operating under WordPress where user ID 1 serves as the administrator.

In light of this discovery, it is crucial for users to update their installations to the most recent patched version of User Profile Builder, which is 3.16.5 at the time of this announcement. The following timeline highlights key events concerning the vulnerability:

  • July 14, 2026 – Submission received for the Authentication Bypass vulnerability via the Wordfence Bug Bounty Program.
  • July 15, 2026 – Report validation and proof-of-concept exploit confirmation.
  • July 15, 2026 – Full disclosure sent to vendor via Wordfence Vulnerability Management Portal.
  • July 15, 2026 – Firewall protection introduced for Wordfence Premium, Care, and Response users.
  • July 16, 2026 – Vendor acknowledges report and releases patched version 3.16.5.
  • August 14, 2026 – Free version users receive firewall protection.

In summary, an Authentication Bypass vulnerability impacting the User Profile Builder plugin has been thoroughly addressed in version 3.16.5. Users are strongly urged to ensure their sites are updated to protect against this critical vulnerability.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...