WordPress security changelog
MEDIUM CVE-2026-82607 Deferred

Profile Builder permits unauthenticated avatar file uploads

Profile Builder 3.16.0 and 3.16.1 exposes the wppb_ajax_simple_avatar function through /wp-admin/admin-ajax.php without requiring authentication. A remote attacker can manipulate the Avatar Simple Upload AJAX handler to upload an unrestricted file to the site. The CNA reports that a public exploit is available.

CVE / CNA score 5.5 CVSS 4.0 · cna@vuldb.com
NVD score Pending NVD has not published its own CVSS assessment.
Component
Profile Builder Plugin
Plugin slug
profile-builder
Affected
3.16.0, 3.16.1
Safe version
3.16.2
Published
Aug 31, 2026
Weakness
CWE-284 — Improper Access Control
CWE-434 — Unrestricted Upload of File with Dangerous Type

This CVE was published Aug 31, 2026 and is one of 29 known issues for this plugin.

Update, patch or deactivate.

Update Profile Builder to 3.16.2 or later and inspect uploaded media and server files for unexpected content if the vulnerable versions were publicly reachable.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 3.16.2 is sufficient to resolve this issue. It is suggested to upgrade the affected component.

CVE / CNA vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Primary and upstream sources