← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 14, 2026 · 18:30via Malware.news

40,000 WordPress Sites affected by Authentication Bypass Vulnerability in User Profile Builder WordPress Plugin

Brief

On July 14th, 2026, we received a submission for an Authentication Bypass vulnerability in User Profile Builder , a WordPress plugin with more than 40,000 active installations. This vulnerability makes it possible for unauthenticated attackers to log in as the user with ID 1, which is typically the site administrator, resulting in full administrative takeover of the site.

The vulnerability is only exploitable on sites where the plugin’s Automatically Log In setting is enabled.

Props to Supakiad S. (m3ez) who discovered and responsibly reported this vulnerability through the Wordfence Bug Bounty Program . This researcher earned a bounty of $975. 00 for this discovery. Our mission is to secure WordPress through defense in depth, which is why we are investing in quality vulnerability research and collaborating with researchers of this caliber through our Bug Bounty Program.

Read more on Malware.news