Critical Flaws in WordPress Forminator and User Profile Builder
Score: 8/10

Critical Flaws in WordPress Forminator and User Profile Builder

Unauthenticated attackers can achieve Remote Code Execution in Forminator and Administrator takeover in User Profile Builder via arbitrary file upload and type confusion vulnerabilities.

Executive Summary

Two critical vulnerabilities, CVE-2026-15748 and CVE-2026-15826, have been identified affecting over 640,000 WordPress installations via the Forminator and User Profile Builder plugins. CVE-2026-15748 in Forminator allows unauthenticated attackers to upload executable PHP files by bypassing extension blocklists using pipe-alternative MIME keys. CVE-2026-15826 in User Profile Builder enables unauthenticated administrative takeover through a type confusion flaw where oversized usernames (61-70 characters) cause the plugin to issue an authentication nonce for User ID 1 (typically the site administrator).

Technically, Forminator's flaw resides in the 'handle_file_upload()' function due to insufficient validation against forged Select field values, while User Profile Builder's flaw stems from the 'wppb_log_in_user()' function incorrectly coercing a WP_Error object into an integer (1) via 'absint()'. Both vulnerabilities have a CVSS score of 9.8.

Successful exploitation of these flaws leads to complete site compromise, enabling attackers to install backdoors, exfiltrate data, or create new administrative accounts. Organizations using these plugins should immediately update to Forminator version 1.56.2 and User Profile Builder version 3.16.5.

Key Details

Threat Name

CVE-2026-15748

Affects

Forminator Forms plugin versions before and including 1.56.1, User Profile Builder plugin versions prior to 3.16.5, User Profile Builder <= 3.16.4, Forminator Forms <= 1.56.1

Adversary

—

Malware/Tools

None identified

Report Score

8out of 10
Quality Score
Good
IOC Quality4
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure9
Technical Depth10

Sources