Critical CVEs Disclosed for WordPress Plugins: CVE-2026-16502 and CVE-2026-6431

Critical CVEs Disclosed for WordPress Plugins: CVE-2026-16502 and CVE-2026-6431

First seen 8 Sep 2026, 15:46 UTC Redpacketsecurity 57.1

Article Content

Browse articles
ThreatCluster

Two significant vulnerabilities affecting WordPress plugins have been disclosed. CVE-2026-16502 in the Live Composer plugin allows authenticated attackers to exploit PHP Object Injection, potentially leading to code execution if a compatible gadget chain is present. CVE-2026-6431 in the User Profile Builder plugin enables unauthenticated attackers to inject malicious scripts via the 'Biographical Info' field, posing risks of account compromise and session theft. Both vulnerabilities affect various WordPress installations, particularly those with public registration and multiple plugins. Immediate patching is recommended, although active exploitation has not been confirmed for either CVE. The urgency of the threats is underscored by the potential for significant impact on affected sites.

Key Points: • CVE-2026-16502 allows PHP Object Injection in Live Composer plugin for WordPress. • CVE-2026-6431 enables Stored XSS in User Profile Builder plugin, affecting user profiles. • Immediate patching is crucial due to the potential for exploitation in vulnerable setups.

Ask AI about this cluster

Timeline

2026-09-07
CVE-2026-6431 published
User Profile Builder plugin vulnerability disclosed, allowing stored XSS attacks.
Redpacketsecurity
2026-09-08
CVE-2026-16502 published
Live Composer plugin vulnerability disclosed, allowing PHP Object Injection for authenticated users.
Redpacketsecurity