VYPR
Unrated severityNVD Advisory· Published Aug 1, 2026

Profile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login After Registration

CVE-2026-15368

Description

The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.