← back

CVE-2026-15368

hype MOSTLY HYPE · 28 hack

Day-zero chatter lacks PoC, KEV listing, or vendor patch signal; config limitation reduces urgency.

What: User Profile Builder WordPress plugin (before 3.16.4) improperly binds post-registration automatic login sessions, allowing unauthenticated attackers to hijack arbitrary user accounts including admins in non-default configurations.

Why it matters: Published today with no CVSS/EPSS assigned and not yet KEV-listed. Social chatter is multilingual and alarmist ("CRITICAL," "account hijacking") but lacks working PoC links or vendor patch confirmation. The vulnerability requires a specific non-default config, limiting real-world blast radius. No defender triage reports visible.

Where it's seen: Early multilingual posts on social platforms (Hebrew, Russian, English) with generic threat language. No linked PoCs, no plugin developer advisory URLs, no WordPress.org security notice referenced.

RISK: MODERATE — Non-default config required; no patch confirmation yet; plugin ecosystem reach unclear.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 8/1/2026, 3:03:12 PM

Description

The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration.