CVE-2026-82607: Cozmoslabs Profile Builder Plugin Avatar Simple Upload AJAX admin-ajax.php wppb_ajax_simple_avatar unrestricted upload
A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppbajaxsimpleavatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 3.16.2 is sufficient to resolve this issue. It is suggested to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cozmoslabs Profile Builder Pluginto a version that resolves this vulnerability.Fixed in 3.16.2
Event History
Frequently Asked Questions
Which versions need remediation?
Cozmoslabs Profile Builder Plugin versions up to and including 3.16.1 are affected. Upgrading the plugin to version 3.16.2 resolves the issue.
Can this be exploited remotely without credentials?
Yes. The supplied severity vector indicates network attack access, low attack complexity, no privileges required, and no user interaction required. The affected upload handler is reached through WordPress admin-ajax.php.
Is there evidence of public exploit availability?
Yes. The vulnerability information states that an exploit has been made public and could be used.