Cozmoslabs security patch release for CVE-2026-15826
Security Patch Release
Summary
Hide ▲
Show ▼
Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw in versions up to and including 3.16.4 that could let unauthenticated attackers reach an administrator session on vulnerable configurations. Site owners should update to 3.16.5 or later to remove the exposure.
Related Happenings
Vercel security patch release for CVE-2026-75604
Security Patch Release
H score33
First: 27.08.2026 18:13
Last: 27.08.2026 18:13
Sources 1
About this happening:
Vercel released Next.js security patches for two critical vulnerabilities that could permit unauthenticated remote code execution in affected deployments. The fixe...
Vercel security patch release for CVE-2026-75604
Security Patch ReleaseAbout this happening: Vercel released Next.js security patches for two critical vulnerabilities that could permit unauthenticated remote code execution in affected deployments. The fixe...
ThemeFusion security patch release for CVE-2026-18431
Security Patch Release
H score43
First: 27.08.2026 00:33
Last: 27.08.2026 00:33
Sources 1
About this happening:
ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
ThemeFusion security patch release for CVE-2026-18431
Security Patch ReleaseAbout this happening: ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
JFrog security patch release for CVE-2026-69106
Security Patch Release
H score30
First: 20.08.2026 17:30
Last: 20.08.2026 17:30
Sources 1
About this happening:
JFrog has issued fixes for JFrog Artifactory after disclosure of CVE-2026-69106 and CVE-2026-65922, two flaws that could let anonymous or low-privileged users...
JFrog security patch release for CVE-2026-69106
Security Patch ReleaseAbout this happening: JFrog has issued fixes for JFrog Artifactory after disclosure of CVE-2026-69106 and CVE-2026-65922, two flaws that could let anonymous or low-privileged users...
Elementor Pro 4.2.2 security update for CVE-2026-32475
Security Patch Release
H score27
First: 20.08.2026 09:04
Last: 20.08.2026 09:04
Sources 1
About this happening:
Elementor Pro released version 4.2.2 to fix CVE-2026-32475, closing an unauthenticated file-upload RCE path in the WordPress plugin. The update targets the Forms mod...
Elementor Pro 4.2.2 security update for CVE-2026-32475
Security Patch ReleaseAbout this happening: Elementor Pro released version 4.2.2 to fix CVE-2026-32475, closing an unauthenticated file-upload RCE path in the WordPress plugin. The update targets the Forms mod...
WordPress security patch release for CVE-2026-64638
Security Patch Release
H score34
First: 07.08.2026 15:56
Last: 07.08.2026 15:56
Sources 1
About this happening:
WordPress 7.0.3 shipped a security fix for CVE-2026-64638, and the release was backported through the 4.7 branch. WordPress urged operators to update immediately a...
WordPress security patch release for CVE-2026-64638
Security Patch ReleaseAbout this happening: WordPress 7.0.3 shipped a security fix for CVE-2026-64638, and the release was backported through the 4.7 branch. WordPress urged operators to update immediately a...
Timeline
-
17.08.2026 16:30 1 articles · 13d ago
Wordfence receives vulnerability report for CVE-2026-15826 in User Profile Builder
Initial DisclosureWordfence received a vulnerability report about an authentication bypass in the User Profile Builder plugin tracked as CVE-2026-15826, exposing more than 40,000 WordPress sites to administrator-account access on vulnerable configurations.
Show sources
- WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — www.infosecurity-magazine.com — 17.08.2026 16:30
-
17.08.2026 16:30 1 articles · 13d ago
Wordfence validates type confusion in User Profile Builder registration flow
Technical Analysis UpdateWordfence validated the flaw the following day and traced it to a type confusion error in User Profile Builder’s registration and automatic-login flow, where a failed account-creation result could be converted into an integer and treated as user ID 1, allowing an attacker to obtain an administrator session when the affected site used that configuration.
Show sources
- WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — www.infosecurity-magazine.com — 17.08.2026 16:30
-
17.08.2026 16:30 2 articles · 13d ago
Cozmoslabs releases User Profile Builder 3.16.5 to fix CVE-2026-15826
Mitigation Patch UpdateCozmoslabs acknowledged the report and released User Profile Builder version 3.16.5 to address CVE-2026-15826, with affected site owners advised to update to version 3.16.5 or later to remove the vulnerable code path.
Show sources
- WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — www.infosecurity-magazine.com — 17.08.2026 16:30
- WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — www.infosecurity-magazine.com — 17.08.2026 16:30