SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76548

HIGH · CVSS 8.2 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The User Profile Builder plugin for WordPress prior to version 4.0.1 has a vulnerability that improperly restricts its front-end file upload feature, enabling unauthenticated users to access functionalities typically reserved for privileged roles. This flaw allows unauthorized individuals to list the site's media library and modify unpublished content belonging to other users. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized access and content manipulation.

CVE
CVE-2026-76548
Severity
HIGH
CVSS
8.2
EPSS
0.19%
WordPress

Original NVD Description

The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.