Junglewise Threat Intelligence

CVE-2026-82607: Cozmoslabs Profile Builder unrestricted file upload in avatar handler

CVE-2026-82607 · Severity: high · CVSS 7.3 · Published 2026-08-31

Executive brief

Profile Builder is a popular WordPress plugin that allows users to create custom registration and profile forms. A flaw in the avatar upload feature permits attackers to upload arbitrary files to the server without authentication or proper validation, potentially enabling code execution, malware distribution, or website compromise.

Technical details

The vulnerability exists in the wppb_ajax_simple_avatar function within the Avatar Simple Upload AJAX Handler component (/wp-admin/admin-ajax.php) of Profile Builder up to version 3.16.1. The flaw is an unrestricted file upload issue that lacks proper input validation and authentication checks, allowing remote attackers to upload malicious files without credentials. The attack is network-accessible and does not require prior authentication or user interaction. An attacker can achieve arbitrary file upload, which may lead to remote code execution, website defacement, or further compromise. The vulnerability was patched in version 3.16.2 and users are advised to upgrade immediately.

Affected products

  • Cozmoslabs Profile Builder up to 3.16.1

Timeline

  • 2026-08-31: disclosed
  • 2026-08-31: patched: Fixed in version 3.16.2

References

Related threats