Junglewise Threat Intelligence

CVE-2026-66701: WordPress Profile Builder broken access control

CVE-2026-66701 · Severity: medium · CVSS 5.3 · Published 2026-08-06

Executive brief

WordPress Profile Builder is a popular plugin for creating user registration and profile management systems on WordPress sites. An unauthenticated vulnerability allows attackers to bypass access controls and view or manipulate user data they should not have permission to access, potentially exposing sensitive customer or member information.

Technical details

The vulnerability is a broken access control flaw in WordPress Profile Builder versions 3.16.5 and earlier that permits unauthenticated attackers to access pages and perform actions they should not be authorized to execute. The root cause involves insufficient permission checks on user-facing functionality, allowing an attacker to access other users' profile data via network-based requests without authentication. An attacker can retrieve sensitive user information including profile details, potentially leading to unauthorized data disclosure. The vulnerability was patched in version 3.16.6.

Affected products

  • Cozmoslabs Profile Builder <=3.16.5

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: patched: Patched in version 3.16.6

References

Related threats