
Critical WordPress Plugin Vulnerability Exposes 40,000 Sites to Admin Takeovers
CybersecurityVulnerabilitiesHackingWebSecurity
A critical vulnerability in the WordPress plugin User Profile Builder exposed approximately 40,000 websites to unauthenticated admin account takeovers. The flaw allowed attackers to bypass authentication and gain administrative privileges without credentials. No specific CVE ID was mentioned in the report, nor were exact dates for the discovery or patch release provided. The issue affected sites using the plugin, though the article did not specify versions or technical exploitation details. The impact included full site compromise, enabling malicious actors to install backdoors, steal data, or deface websites. The source of the disclosure was not explicitly named.