CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5972

As cited

Copy frozen at (site build).

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin allows unauthenticated attackers to access administrator accounts. The flaw affects approximately 40,000 WordPress sites running the plugin. The vulnerability exposes affected sites to full administrative compromise and data exfiltration.

Why it matters: WordPress site administrators and hosting providers managing sites with User Profile Builder must immediately identify and patch affected installations to prevent unauthorized admin account access and site takeover.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin allows unauthenticated attackers to access administrator accounts. The flaw affects approximately 40,000 WordPress sites running the plugin. The vulnerability exposes affected sites to full administrative compromise and data exfiltration.

Why it matters: WordPress site administrators and hosting providers managing sites with User Profile Builder must immediately identify and patch affected installations to prevent unauthorized admin account access and site takeover.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary