{
 "description": "Evidence-bound MITRE ATT&CK techniques observed in ctipilot.ch entries referencing Cozmoslabs User Profile Builder (WordPress, 40,000+ installs) \u2014 unauthenticated authentication bypass via type confusion: wppb_log_in_user() calls absint() on the return value of wp_insert_user() before the is_wp_error() check, so a 61-70 character username makes core return a WP_Error that coerces to the integer 1 and the plugin issues an autologin bound to user ID 1. CVSS 9.8, Wordfence as CNA. Exploitable only where the plugin's Automatically Log In setting is enabled. Fixed in 3.16.5 (2026-07-16); write-up 2026-08-14, relayed by NCSC-CH 2026-08-18. No exploitation reported.. Score = number of published entries mapping the technique. Pinned dataset: ATT&CK v19.2.",
 "domain": "enterprise-attack",
 "gradient": {
  "colors": [
   "#ffe766",
   "#ff6666"
  ],
  "maxValue": 1,
  "minValue": 0
 },
 "hideDisabled": false,
 "layout": {
  "layout": "side",
  "showID": true,
  "showName": true
 },
 "legendItems": [],
 "metadata": [
  {
   "name": "source",
   "value": "ctipilot.ch"
  },
  {
   "name": "entity",
   "value": "CVE-2026-15826"
  },
  {
   "name": "attack_version",
   "value": "19.2"
  }
 ],
 "name": "Cozmoslabs User Profile Builder (WordPress, 40,000+ installs) \u2014 unauthenticated authentication bypass via type confusion: wppb_log_in_user() calls absint() on the return value of wp_insert_user() before the is_wp_error() check, so a 61-70 character username makes core return a WP_Error that coerces to the integer 1 and the plugin issues an autologin bound to user ID 1. CVSS 9.8, Wordfence as CNA. Exploitable only where the plugin's Automatically Log In setting is enabled. Fixed in 3.16.5 (2026-07-16); write-up 2026-08-14, relayed by NCSC-CH 2026-08-18. No exploitation reported. \u2014 ctipilot.ch coverage",
 "sorting": 3,
 "techniques": [
  {
   "comment": "entries: 2026-08-19/cve-2026-15826-user-profile-builder-type-confusion-admin",
   "score": 1,
   "techniqueID": "T1078.003"
  },
  {
   "comment": "entries: 2026-08-19/cve-2026-15826-user-profile-builder-type-confusion-admin",
   "score": 1,
   "techniqueID": "T1190"
  },
  {
   "showSubtechniques": true,
   "techniqueID": "T1078"
  }
 ],
 "versions": {
  "attack": "19",
  "layer": "4.5",
  "navigator": "5.1.0"
 }
}