CVE-2026-15826 is a critical authentication bypass vulnerability in the User Profile Builder WordPress plugin (versions prior to 3.16.5). It allows unauthenticated attackers to log in as the site administrator (user ID 1) when the Automatically Log In setting is enabled. The flaw is caused by improper error handling in the wppb_log_in_user() function. Patched in version 3.16.5.