CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-15368

unknowncovered by 1 sourcefirst seen 2026-08-01
The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration.

⚡ Watch CVE-2026-15368

Get an email if CVE-2026-15368 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-15368

CVE.org record

Embed the live status

CVE-2026-15368 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-15368 status](https://www.csirts.com/badge/CVE-2026-15368)](https://www.csirts.com/cve/CVE-2026-15368)