SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76547

MEDIUM · CVSS 6.6 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The User Profile Builder plugin for WordPress prior to version 4.0.1 is vulnerable to PHP Object Injection due to improper validation of deserialized data during configuration file imports. This flaw primarily affects high-privilege users, such as administrators, who could exploit it if a compatible gadget from another affected plugin is present. WordPress site administrators using this plugin should prioritize updating to version 4.0.1 or later to mitigate potential risks.

CVE
CVE-2026-76547
Severity
MEDIUM
CVSS
6.6
EPSS
0.25%
WordPress

Original NVD Description

The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is present in the User Profile Builder WordPress plugin before 4.0.1 itself, so further impact requires a suitable gadget from another installed User Profile Builder WordPress plugin before 4.0.1 or .