top of page
perceptive_background_267k.jpg

A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the fi…

Published:

31 August 2026 at 00:00:00

Alert date:

31 August 2026 at 23:17:03

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

A critical unrestricted file upload vulnerability has been identified in the Cozmoslabs Profile Builder Plugin for WordPress, affecting versions up to 3.16.1. The vulnerability resides in the wppb_ajax_simple_avatar function within the Avatar Simple Upload AJAX Handler component at /wp-admin/admin-ajax.php. An unauthenticated remote attacker can exploit this flaw to upload arbitrary files to the server, potentially leading to remote code execution. The exploit has been publicly disclosed, increasing the risk of active exploitation in the wild. The vulnerability has been assigned CVE-2026-82607 and is rated as high severity. WordPress site administrators running affected versions are strongly advised to upgrade to version 3.16.2, which resolves the issue. No workaround is documented other than upgrading the plugin.

Technical details

Mitigation steps:

Affected products:

Cozmoslabs Profile Builder Plugin up to 3.16.1
WordPress

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page