CVE-2026-76548

The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-29 06:17

Updated : 2026-08-31 20:14


NVD link : CVE-2026-76548

Mitre link : CVE-2026-76548

CVE.ORG link : CVE-2026-76548


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication