EUVD-2026-68051
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is disabled by default, and no POP chain is present in the User Profile Builder WordPress plugin before 4.0.1 itself, so further impact requires a suitable gadget from another installed User Profile Builder WordPress plugin before 4.0.1 or .
- EUVD state
- Present in the current official mapping
- Known exploitation
- Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
- ENISA score
- 6.6 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
