TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/User Profile Builder’s Auto-Login Bug Exposes 40,000 WordPress Sites to Account Takeover
News

User Profile Builder’s Auto-Login Bug Exposes 40,000 WordPress Sites to Account Takeover

An authentication bypass in the User Profile Builder WordPress plugin, tracked as CVE-2026-15368, lets attackers hijack existing accounts on sites that enable its automatic login after registration...

August 14, 2026 3 Min Read
52

Wordfence is warning WordPress site owners about an authentication bypass vulnerability in User Profile Builder, a Cozmoslabs plugin for user registration forms, profile editing, and role management that is active on more than 40,000 WordPress sites. Tracked as CVE-2026-15368, the flaw lets an unauthenticated attacker obtain a logged-in session belonging to an existing user, including a site administrator, on installations that use the plugin’s automatic-login-after-registration feature. The National Vulnerability Database scores the bug 8.1 out of 10 (High) on the CVSS 3.1 scale. Cozmoslabs fixed the issue in version 3.16.4, and the plugin is currently at version 3.16.6 on the WordPress.org plugin directory.

Table Of Content

  • How the Bug Works
  • Who Is Actually Exposed
  • What Site Owners Should Do Now

How the Bug Works

User Profile Builder includes an optional setting that logs a visitor straight into their new account the moment they submit a registration form. According to Cozmoslabs’ own documentation, that automatic login option is off by default and has to be turned on through the plugin’s general settings, an individual registration form’s settings, or a shortcode attribute.

NVD’s advisory describes what goes wrong when the option is on: the plugin “does not correctly bind the automatic login performed after user registration to the newly created account,” which lets an unauthenticated visitor end up logged in as a different, arbitrary existing user rather than the account they just registered, up to and including an administrator. WPScan, which tracks the same CVE in its own vulnerability database, classifies it as an unauthenticated account takeover and credits researcher Jakub Herman with the discovery. The CVSS vector NVD publishes, AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, marks attack complexity as high, meaning exploitation depends on conditions the attacker does not fully control rather than a single, reliably repeatable request.

Who Is Actually Exposed

The real-world exposure is narrower than the plugin’s 40,000-plus install count implies. Because automatic login after registration is an opt-in setting, only sites where an administrator has switched it on are vulnerable to this specific flaw. A site running User Profile Builder purely for its default registration forms, profile editing, and user role management, without that toggle enabled, does not expose the vulnerable code path. That distinction is why NVD’s advisory qualifies the affected setup as “supported but non-default” instead of describing every installation as at risk.

What Site Owners Should Do Now

Cozmoslabs shipped the fix in User Profile Builder 3.16.4, and the plugin has since moved on to 3.16.6, so the patched code has been available through the WordPress.org repository for several weeks. Site owners should:

  • Update User Profile Builder to version 3.16.4 or later (currently 3.16.6) from the WordPress admin dashboard or the WordPress.org plugin page.
  • Check whether automatic login after registration is enabled and, if it is, review recent logins and registrations for accounts that were not expected, especially anything tied to administrator or editor roles.
  • Turn the automatic login setting off if it is not actually needed. That removes the vulnerable code path regardless of which plugin version is installed.

The bug is a reminder that convenience settings on registration and login plugins deserve the same scrutiny as authentication code anywhere else on a site. A feature that silently hands a visitor a session, even a legitimate one, is one binding error away from handing out the wrong session entirely.

Tags:

Account HijackingPlugin VulnerabilityVulnerability DisclosureWordPressWordPress Security

Share

Rows of server racks seen from above in a data center, representing the physical hardware layer beneath AI inference and agent systems
Previous Post

Red Hat’s Metal to Agents Framework Turns AI Token Growth Into an Infrastructure Bet

The C-Lion1 submarine fiber optic cable landing station building in Rostock-Markgrafenheide, Germany
Next Post

DigitalOcean’s Data Locality Tax Turns RAG Latency Into a Geography Problem

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026