---
id: CVE-2026-76548
title: >-
  The User Profile Builder  WordPress plugin before 4.0.1 does not properly
  restrict its front-end file upload feature, granting unauthenticated visitors
  capabilities reserved to privileged roles
summary: >-
  The User Profile Builder  WordPress plugin before 4.0.1 does not properly
  restrict its front-end file upload feature, granting unauthenticated visitors
  capabilities reserved to privileged roles. This allows them to list the site's
  media …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-287
published: '2026-08-29'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76548'
references:
  - url: 'https://wpscan.com/vulnerability/75e0611d-e11d-44f8-8fc1-7c40bb113f64/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00187
epssPercentile: 0.08566
ingestedAt: '2026-08-30T07:49:07.255Z'
---

## Overview

The User Profile Builder  WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
