Profile Builder could turn a failed registration into an administrator autologin link, while BitFire authentication RASP prevents unauthenticated requests from minting WordPress auth cookies.
Affected sites
50,000+
Attack class
Authentication Bypass
BitFire protectionProtected by BitFire Authentication RASP
BitFire blocks automated exploit requests and uses PRO RASP to prevent CVE-2026-15158 from creating an unauthorized PHP file through Blocksy Companion Pro.
AI Engine exposes its MCP bearer token in public REST API discovery data, while BitFire PRO RASP prevents an MCP request authenticated only by that plugin token from creating a new administrator account.