Description
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.
Published: 2026-08-29
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated privilege escalation allowing modification of unpublished content and media
Action: Immediate Patch
AI Analysis

Impact

The User Profile Builder plugin for WordPress contains an access control flaw that lets unauthenticated visitors exploit its front‑end file upload feature. The vulnerability permits listing the site’s media library and editing unpublished posts, pages, and media items belonging to other users. These capabilities expose the integrity of content and media, enabling an attacker to inject or replace files and alter the site’s data without authorization.

Affected Systems

WordPress sites running the User Profile Builder plugin prior to version 4.0.1 are affected. Anyone who has not yet upgraded the plugin should consider the application as vulnerable if the specified plugin is installed.

Risk and Exploitability

An attacker can simply visit the front‑end media upload interface, which is exposed to all visitors, to trigger the exploit. Because the plugin does not verify user roles before allowing uploads or edits, the threat model is a remote, unauthenticated attack with high potential to compromise content integrity. The CVSS score of 8.2 indicates a high severity risk. The EPSS score of <1% suggests a low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 30, 2026 at 02:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update User Profile Builder to version 4.0.1 or later, which removes the unrestricted front‑end upload bug
  • If an upgrade is not immediately possible, disable the front‑end media upload capability entirely through plugin settings or by removing the upload form from the site CMS
  • Restrict the media upload permission to trusted roles only and monitor the upload activity logs for any suspicious unauthorized uploads

Generated by OpenCVE AI on August 30, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 29 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 29 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.
Title Profile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth Bypass
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-30T00:56:52.128Z

Reserved: 2026-08-19T12:04:02.085Z

Link: CVE-2026-76548

cve-icon Vulnrichment

Updated: 2026-08-30T00:49:05.876Z

cve-icon NVD

Status : Deferred

Published: 2026-08-29T06:17:29.450

Modified: 2026-08-31T20:14:36.250

Link: CVE-2026-76548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T02:30:06Z

Weaknesses