WordPress Plugin Vulnerabilities

Profile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login After Registration

Description

The plugin does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration.

Proof of Concept

Affects Plugins

Fixed in 3.16.4

References

Classification

Miscellaneous

Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-07-17 (about 1 month ago)
Added
2026-07-17 (about 1 month ago)
Last Updated
2026-08-21 (about 1 day ago)

Other