{"api_version":"1","generated_at":"2026-08-29T12:12:03+00:00","cve":"CVE-2026-76548","urls":{"html":"https://cve.report/CVE-2026-76548","api":"https://cve.report/api/cve/CVE-2026-76548.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-76548","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-76548"},"summary":{"title":"Profile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth Bypass","description":"The User Profile Builder  WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-29 06:17:29","updated_at":"2026-08-29 06:17:29"},"problem_types":["CWE-287 Improper Authentication"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/75e0611d-e11d-44f8-8fc1-7c40bb113f64/","name":"https://wpscan.com/vulnerability/75e0611d-e11d-44f8-8fc1-7c40bb113f64/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-76548","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76548","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"User Profile Builder","version":"affected 3.8.1 4.0.1 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Erwan LR (WPScan)","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"User Profile Builder","vendor":"Unknown","versions":[{"lessThan":"4.0.1","status":"affected","version":"3.8.1","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Erwan LR (WPScan)"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The User Profile Builder  WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users."}],"problemTypes":[{"descriptions":[{"description":"CWE-287 Improper Authentication","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-29T06:00:20.799Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/75e0611d-e11d-44f8-8fc1-7c40bb113f64/"}],"source":{"discovery":"EXTERNAL"},"title":"Profile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth Bypass","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-76548","datePublished":"2026-08-29T06:00:20.799Z","dateReserved":"2026-08-19T12:04:02.085Z","dateUpdated":"2026-08-29T06:00:20.799Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-29 06:17:29","lastModifiedDate":"2026-08-29 06:17:29","problem_types":["CWE-287 Improper Authentication"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"76548","Ordinal":"1","Title":"Profile Builder < 4.0.1 - Unauthenticated Unpublished Content an","CVE":"CVE-2026-76548","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"76548","Ordinal":"1","NoteData":"The User Profile Builder  WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.","Type":"Description","Title":"Profile Builder < 4.0.1 - Unauthenticated Unpublished Content an"}]}}}