{"id":"CVE-2026-76547","title":"The User Profile Builder  WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection","summary":"The User Profile Builder  WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The …","severity":"medium","cvss":6.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-502"],"published":"2026-08-29","updated":"2026-08-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76547","references":[{"url":"https://wpscan.com/vulnerability/b80151f4-e910-4263-9ecc-470fb39d7583/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00246,"epssPercentile":0.16155,"ingestedAt":"2026-08-30T07:49:07.199Z","slug":"CVE-2026-76547","body":"## Overview\n\nThe User Profile Builder  WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is present in the User Profile Builder  WordPress plugin before 4.0.1 itself, so further impact requires a suitable gadget from another installed User Profile Builder  WordPress plugin before 4.0.1 or .\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":36.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}