2026-08-19NOTABLEA type coercion in the wrong order hands an anonymous registrant the administrator account
Cozmoslabs User Profile Builder (WordPress, 40,000+ installs), unauthenticated authentication bypass via type confusion: wppb_log_in_user() calls absint() on the return value of wp_insert_user() before the is_wp_error() check, so a 61-70 character username makes core return a WP_Error that coerces to the integer 1 and the plugin issues an autologin bound to user ID 1. CVSS 9.8, Wordfence as CNA. Exploitable only where the plugin's Automatically Log In setting is enabled. Fixed in 3.16.5 (2026-07-16); write-up 2026-08-14, relayed by NCSC-CH 2026-08-18. No exploitation reported.
cve · CVE-2026-15826
Coverage
1
first 2026-08-19 → last 2026-08-19
Latest activity
2026-08-19
A type coercion in the wrong order hands an anonymous registrant the administrator account
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, education, technology · regions: europe, switzerland
Sources cited
3
3 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-15826, newest first. Check the date before acting on an older one.
- Update User Profile Builder to 3.16.5 or later; where that cannot be done immediately, disable the plugin's Automatically Log In setting, which Wordfence states is the precondition for exploitability.2026-08-19CVE-2026-15826
- On any affected site that allowed open registration while unpatched, review the administrator account (user ID 1) for sessions, password changes or content changes that do not correspond to a known administrator login.2026-08-19CVE-2026-15826
Defender insights
What each entry about CVE-2026-15826 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 4 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts: Local Accounts · Exploit Public-Facing Application
- PersistenceValid Accounts: Local Accounts
- Privilege EscalationValid Accounts: Local Accounts
- StealthValid Accounts: Local Accounts
Initial Access TA0001
T1078.003Valid Accounts: Local Accounts×1
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Evidence: 2026-08-19/cve-2026-15826-user-profile-builder-type-confusion-admin · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-19/cve-2026-15826-user-profile-builder-type-confusion-admin · ATT&CK page ↗
Persistence TA0003
T1078.003Valid Accounts: Local Accounts×1
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Evidence: 2026-08-19/cve-2026-15826-user-profile-builder-type-confusion-admin · ATT&CK page ↗
Privilege Escalation TA0004
T1078.003Valid Accounts: Local Accounts×1
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Evidence: 2026-08-19/cve-2026-15826-user-profile-builder-type-confusion-admin · ATT&CK page ↗
Stealth TA0005
T1078.003Valid Accounts: Local Accounts×1
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Evidence: 2026-08-19/cve-2026-15826-user-profile-builder-type-confusion-admin · ATT&CK page ↗
Entries about Cozmoslabs User Profile Builder (WordPress, 40,000+ installs), unauthenticated authentication bypass via type confusion: wppb_log_in_user() calls absint() on the return value of wp_insert_user() before the is_wp_error() check, so a 61-70 character username makes core return a WP_Error that coerces to the integer 1 and the plugin issues an autologin bound to user ID 1. CVSS 9.8, Wordfence as CNA. Exploitable only where the plugin's Automatically Log In setting is enabled. Fixed in 3.16.5 (2026-07-16); write-up 2026-08-14, relayed by NCSC-CH 2026-08-18. No exploitation reported. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- malware.news1 (33%)
- security-hub.ncsc.admin.ch1 (33%)
- thehackernews.com1 (33%)
External references
All cited sources (3)
- security-hub.ncsc.admin.chprimaryNCSC-CH Cyber Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12860
- malware.newsmalware.news (verbatim syndication of the Wordfence Intelligence post)https://malware.news/t/40-000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-user-profile-builder-wordpress-plugin/124811
- thehackernews.comThe Hacker News (quoting Wordfence)https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html