CVE-2026-82607 | Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress Avatar Simple Upload AJAX /wp-admin/admin-ajax.php wppb_ajax_simple_avatar unrestricted upload
A vulnerability marked as critical has been reported in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload.
This vulnerability is reported as CVE-2026-82607. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More