


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the fi…
Published:
31 August 2026 at 00:00:00
Alert date:
31 August 2026 at 23:17:03
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A critical unrestricted file upload vulnerability has been identified in the Cozmoslabs Profile Builder Plugin for WordPress, affecting versions up to 3.16.1. The vulnerability resides in the wppb_ajax_simple_avatar function within the Avatar Simple Upload AJAX Handler component at /wp-admin/admin-ajax.php. An unauthenticated remote attacker can exploit this flaw to upload arbitrary files to the server, potentially leading to remote code execution. The exploit has been publicly disclosed, increasing the risk of active exploitation in the wild. The vulnerability has been assigned CVE-2026-82607 and is rated as high severity. WordPress site administrators running affected versions are strongly advised to upgrade to version 3.16.2, which resolves the issue. No workaround is documented other than upgrading the plugin.
Technical details
Mitigation steps:
Affected products:
Cozmoslabs Profile Builder Plugin up to 3.16.1
WordPress
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82607
https://ciphersecuritylabs.com/research/articles/when-the-browser-is-the-only-bouncer-unauthenticated-media-upload-in-profile-builder
https://vuldb.com/cve/CVE-2026-82607
https://vuldb.com/submit/892841
https://vuldb.com/vuln/397108
https://vuldb.com/vuln/397108/cti
https://www.cozmoslabs.com/docs/profile-builder/free-changelog/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
