{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/profile-builder-plugin--3.16.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cozmoslabs:profile_builder_plugin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-82607"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Profile Builder Plugin (\u003c= 3.16.1)"],"_cs_severities":["high"],"_cs_tags":["wordpress","web-application","rce","file-upload"],"_cs_type":"advisory","_cs_vendors":["Cozmoslabs"],"content_html":"\u003cp\u003eThe Cozmoslabs Profile Builder plugin for WordPress, in versions up to and including 3.16.1, contains an unrestricted file upload vulnerability. This flaw resides in the 'wppb_ajax_simple_avatar' function within the 'admin-ajax.php' component, which handles simple avatar uploads. Because the handler fails to properly validate the type or content of uploaded files, a remote, unauthenticated attacker can upload arbitrary files to the web server. If the target server is configured to execute files within the upload directory, this vulnerability can be leveraged to achieve remote code execution (RCE). The vulnerability has been publicly disclosed with functional exploit code available. Administrators are advised to update the Profile Builder plugin to version 3.16.2 or later to remediate this issue.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify WordPress sites running vulnerable versions of the Profile Builder plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a multipart/form-data HTTP POST request targeting /wp-admin/admin-ajax.php.\u003c/li\u003e\n\u003cli\u003eAttacker includes the action parameter set to trigger the 'wppb_ajax_simple_avatar' handler.\u003c/li\u003e\n\u003cli\u003eAttacker embeds a malicious script (e.g., a PHP webshell) within the file upload field of the request.\u003c/li\u003e\n\u003cli\u003eThe server-side code fails to validate the extension or MIME type of the uploaded file.\u003c/li\u003e\n\u003cli\u003eThe malicious file is stored on the server's filesystem, typically within the WordPress uploads directory or a subdirectory utilized by the plugin.\u003c/li\u003e\n\u003cli\u003eAttacker triggers execution of the uploaded file by navigating to its direct URL path.\u003c/li\u003e\n\u003cli\u003eAttacker gains arbitrary command execution in the context of the web server user.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full remote code execution on the underlying web server. This leads to complete compromise of the WordPress site, potential exfiltration of database contents, persistent backdoors, and possible lateral movement into the hosting environment. This vulnerability affects any organization running the vulnerable plugin version on a publicly accessible WordPress instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for defense:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Profile Builder plugin to version 3.16.2 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit existing files in the WordPress uploads directory for suspicious PHP files if compromise is suspected.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to inspect and block anomalous POST requests targeting /wp-admin/admin-ajax.php with suspicious file extensions in the payload.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect attempts to invoke the vulnerable AJAX handler.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T05:14:23Z","date_published":"2026-08-31T05:14:23Z","id":"https://feed.craftedsignal.io/briefs/2026-08-profile-builder-rce/","summary":"An unauthenticated remote file upload vulnerability in the Cozmoslabs Profile Builder WordPress plugin (CVE-2026-82607) allows remote attackers to upload arbitrary files to the server via admin-ajax.php.","title":"Unrestricted File Upload in Cozmoslabs Profile Builder Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-profile-builder-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Profile Builder Plugin (\u003c= 3.16.1)","version":"https://jsonfeed.org/version/1.1"}