Unauthenticated WordPress admin takeover via forged autologin-1- nonce (CVE-2026-15826)
Detects unauthenticated WordPress administrator account takeover attempts targeting the User Profile Builder plugin. The rule identifies inbound HTTP GET requests containing the 'autologin=true' parameter and a forged '_wpnonce' value matching the 'autologin-1-' pattern, which exploits an authentication bypass vulnerability (CVE-2026-15826) to gain unauthorized session access as user ID 1.
Microsoft Sentinel (KQL)

