WordPress User Profile Builder oversized-username auth bypass (CVE-2026-15826)
This rule detects potential exploitation of CVE-2026-15826, an authentication bypass vulnerability in the WordPress User Profile Builder plugin. It monitors HTTP POST requests to 'admin-ajax.php' or the 'profile-builder' endpoint for username parameters between 61 and 70 characters long, which is a known exploit condition for triggering a type confusion in the wppb_log_in_user() function that could allow unauthorized access as user ID 1.
Microsoft Sentinel (KQL)

