The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is present in the User Profile Builder WordPress plugin before 4.0.1 itself, so further impact requires a suitable gadget from another installed User Profile Builder WordPress plugin before 4.0.1 or .
History

Sun, 30 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 29 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Sat, 29 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is present in the User Profile Builder WordPress plugin before 4.0.1 itself, so further impact requires a suitable gadget from another installed User Profile Builder WordPress plugin before 4.0.1 or .
Title Profile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/Export
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-29T06:00:20.618Z

Updated: 2026-08-30T00:56:52.277Z

Reserved: 2026-08-19T12:03:22.704Z

Link: CVE-2026-76547

cve-icon Vulnrichment

Updated: 2026-08-30T00:49:08.849Z

cve-icon NVD

Status : Deferred

Published: 2026-08-29T06:17:29.343

Modified: 2026-08-31T20:14:36.250

Link: CVE-2026-76547

cve-icon Redhat

No data.