Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.2
CVE-2026-76548: User Profile Builder lets anyone edit site content
CVE-2026-76548 · published 5 days ago
Summary
The User Profile Builder plugin for WordPress (versions before 4.0.1) allows people who are not logged in to upload files and change media, posts, and pages that should be restricted. This could let strangers view your media library and alter unpublished content. Update the plugin to the latest version or remove the file‑upload feature until you can apply the fix.
What to do
- Update unknown user profile builder to version 4.0.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | user profile builder | < 4.0.1 |
Original advisory text
Profile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth Bypass
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.
Severity
8.2
High
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Monitor software like this
Free during beta