CVE-2026-76547: Profile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/Export
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is present in the User Profile Builder WordPress plugin before 4.0.1 itself, so further impact requires a suitable gadget from another installed User Profile Builder WordPress plugin before 4.0.1 or .
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: User Profile Builderto a version that resolves this vulnerability.Fixed in 4.0.1
Event History
Frequently Asked Questions
Who can exploit this issue in a typical installation?
An attacker needs high privileges, such as WordPress administrator access, and access to the configuration import feature. The affected free add-on is disabled by default, so installations that have not enabled it are not exposed through this feature.
Does successful exploitation automatically lead to code execution?
No. The plugin itself has no POP chain, so PHP Object Injection requires a suitable gadget chain from another installed component to produce further impact.
What should be prioritized if patching cannot happen immediately?
Disable the affected Import/Export free add-on and restrict administrator-level access, particularly access to configuration imports. Also review other installed plugins for potential deserialization gadget chains.