CVE-2026-76548: Profile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth Bypass
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress User Profile Builder pluginto a version that resolves this vulnerability.Fixed in 4.0.1 - Compensating control
Restrict front-end upload access (for the User Profile Builder WordPress plugin) so unauthenticated visitors cannot use the front-end file upload feature until upgraded to version 4.0.1.
Event History
Frequently Asked Questions
Who can exploit this issue?
Unauthenticated visitors can exploit the affected front-end upload feature. They do not need a WordPress account or privileged site role.
What access could an attacker gain through exploitation?
An attacker can list the site's media library and modify unpublished posts, pages, and media items owned by other users.
Which plugin versions are affected?
User Profile Builder versions before 4.0.1 are affected. Version 4.0.1 is not described as affected by the provided information.