Executive Summary
Two critical vulnerabilities, CVE-2026-15748 and CVE-2026-15826, have been identified affecting over 640,000 WordPress installations via the Forminator and User Profile Builder plugins. CVE-2026-15748 in Forminator allows unauthenticated attackers to upload executable PHP files by bypassing extension blocklists using pipe-alternative MIME keys. CVE-2026-15826 in User Profile Builder enables unauthenticated administrative takeover through a type confusion flaw where oversized usernames (61-70 characters) cause the plugin to issue an authentication nonce for User ID 1 (typically the site administrator).
Technically, Forminator's flaw resides in the 'handle_file_upload()' function due to insufficient validation against forged Select field values, while User Profile Builder's flaw stems from the 'wppb_log_in_user()' function incorrectly coercing a WP_Error object into an integer (1) via 'absint()'. Both vulnerabilities have a CVSS score of 9.8.
Successful exploitation of these flaws leads to complete site compromise, enabling attackers to install backdoors, exfiltrate data, or create new administrative accounts. Organizations using these plugins should immediately update to Forminator version 1.56.2 and User Profile Builder version 3.16.5.
