PT-2026-83681 · Cozmoslabs · Profile-Builder Plugin

·

CVE-2026-82607

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cozmoslabs Profile Builder Plugin versions prior to 3.16.2
Description An unrestricted upload issue exists in the Avatar Simple Upload AJAX Handler component. A remote attacker can manipulate the wppb ajax simple avatar() function within the '/wp-admin/admin-ajax.php' endpoint to upload files without proper restrictions.
Recommendations Update to version 3.16.2.

Exploit

Fix

Unrestricted File Upload

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82607

Affected Products

Profile-Builder Plugin