CVE-2026-82607
Received Received - Intake

Unrestricted File Upload in Cozmoslabs Profile Builder WordPress Plugin

Vulnerability report for CVE-2026-82607, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulDB

Description

A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 3.16.2 is sufficient to resolve this issue. It is suggested to upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
cozmoslabs profile_builder_plugin to 3.16.1 (inc)
cozmoslabs profile_builder to 3.16.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Cozmoslabs Profile Builder Plugin for WordPress up to version 3.16.1. The issue is in the Avatar Simple Upload AJAX Handler function wppb_ajax_simple_avatar located in /wp-admin/admin-ajax.php. It allows unrestricted file uploads due to improper validation, enabling remote attackers to upload malicious files.

Detection Guidance

Check if the Profile Builder plugin version is below 3.16.2. Look for unauthorized file uploads in the /wp-admin/admin-ajax.php endpoint, particularly via the wppb_ajax_simple_avatar function. Inspect server logs for suspicious activity related to avatar uploads.

Impact Analysis

An attacker could exploit this to upload malicious files to your WordPress site, potentially leading to remote code execution, defacement, or malware distribution. It may also allow unauthorized access or data theft depending on the uploaded content.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties or fines.

Mitigation Strategies

Upgrade the Profile Builder plugin to version 3.16.2 or later immediately. Remove any unauthorized files uploaded via the vulnerable function. Monitor for signs of exploitation and review user accounts for anomalies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82607. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart