User Profile Builder’s Auto-Login Bug Exposes 40,000 WordPress Sites to Account Takeover
An authentication bypass in the User Profile Builder WordPress plugin, tracked as CVE-2026-15368, lets attackers hijack existing accounts on sites that enable its automatic login after registration...
Wordfence is warning WordPress site owners about an authentication bypass vulnerability in User Profile Builder, a Cozmoslabs plugin for user registration forms, profile editing, and role management that is active on more than 40,000 WordPress sites. Tracked as CVE-2026-15368, the flaw lets an unauthenticated attacker obtain a logged-in session belonging to an existing user, including a site administrator, on installations that use the plugin’s automatic-login-after-registration feature. The National Vulnerability Database scores the bug 8.1 out of 10 (High) on the CVSS 3.1 scale. Cozmoslabs fixed the issue in version 3.16.4, and the plugin is currently at version 3.16.6 on the WordPress.org plugin directory.
Table Of Content
How the Bug Works
User Profile Builder includes an optional setting that logs a visitor straight into their new account the moment they submit a registration form. According to Cozmoslabs’ own documentation, that automatic login option is off by default and has to be turned on through the plugin’s general settings, an individual registration form’s settings, or a shortcode attribute.
NVD’s advisory describes what goes wrong when the option is on: the plugin “does not correctly bind the automatic login performed after user registration to the newly created account,” which lets an unauthenticated visitor end up logged in as a different, arbitrary existing user rather than the account they just registered, up to and including an administrator. WPScan, which tracks the same CVE in its own vulnerability database, classifies it as an unauthenticated account takeover and credits researcher Jakub Herman with the discovery. The CVSS vector NVD publishes, AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, marks attack complexity as high, meaning exploitation depends on conditions the attacker does not fully control rather than a single, reliably repeatable request.
Who Is Actually Exposed
The real-world exposure is narrower than the plugin’s 40,000-plus install count implies. Because automatic login after registration is an opt-in setting, only sites where an administrator has switched it on are vulnerable to this specific flaw. A site running User Profile Builder purely for its default registration forms, profile editing, and user role management, without that toggle enabled, does not expose the vulnerable code path. That distinction is why NVD’s advisory qualifies the affected setup as “supported but non-default” instead of describing every installation as at risk.
What Site Owners Should Do Now
Cozmoslabs shipped the fix in User Profile Builder 3.16.4, and the plugin has since moved on to 3.16.6, so the patched code has been available through the WordPress.org repository for several weeks. Site owners should:
- Update User Profile Builder to version 3.16.4 or later (currently 3.16.6) from the WordPress admin dashboard or the WordPress.org plugin page.
- Check whether automatic login after registration is enabled and, if it is, review recent logins and registrations for accounts that were not expected, especially anything tied to administrator or editor roles.
- Turn the automatic login setting off if it is not actually needed. That removes the vulnerable code path regardless of which plugin version is installed.
The bug is a reminder that convenience settings on registration and login plugins deserve the same scrutiny as authentication code anywhere else on a site. A feature that silently hands a visitor a session, even a legitimate one, is one binding error away from handing out the wrong session entirely.








No Comment! Be the first one.