---
cve: "CVE-2026-76548"
severity: "HIGH"
cvss: 8.2
epss: "19%"
vendor: "Unknown"
kev: false
exploited: false
published: "2026-08-29 06:17:29"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-03T04:26:17+02:00"
---

# CVE-2026-76548

> 8.2 HIGH

## Beschreibung

The User Profile Builder  WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://wpscan.com/vulnerability/75e0611d-e11d-44f8-8fc1-7c40bb113f64/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-76548) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
