Junglewise Threat Intelligence

CVE-2026-76548: User Profile Builder authentication bypass in file upload

CVE-2026-76548 · Severity: high · CVSS 8.2 · Published 2026-08-29

Technologies: Cozmoslabs User Profile Builder. Vendors: Cozmoslabs.

Executive brief

User Profile Builder is a WordPress plugin that allows website administrators to customize user registration and profile features. The plugin's front-end file upload feature fails to properly authenticate users, allowing unauthenticated visitors to access and modify unpublished content and media files belonging to other users. This could enable attackers to deface or steal sensitive unpublished content without any login credentials.

Technical details

User Profile Builder before version 4.0.1 contains an authentication bypass vulnerability (CWE-287) in its front-end file upload feature. The plugin fails to properly restrict file upload capabilities to authenticated users with appropriate roles, allowing unauthenticated attackers to list the site's media library and modify unpublished posts, pages, and media items belonging to other users. The vulnerability is exploitable remotely over the network without requiring any authentication or user interaction. An attacker can leverage this to enumerate and modify sensitive unpublished content. The fix is available in version 4.0.1 and later.

Affected products

  • Cozmoslabs User Profile Builder before 4.0.1

Timeline

  • 2026-08-27: disclosed
  • 2026-08-29: patched: Fixed in version 4.0.1

References

Related threats