A critical unrestricted file upload vulnerability has been identified in the Cozmoslabs Profile Builder Plugin for WordPress, affecting versions up to 3.16.1. The vulnerability resides in the wppb_ajax_simple_avatar function within the Avatar Simple Upload AJAX Handler component at /wp-admin/admin-ajax.php. An unauthenticated remote attacker can exploit this flaw to upload arbitrary files to the server, potentially leading to remote code execution. The exploit has been publicly disclosed, increasing the risk of active exploitation in the wild. The vulnerability has been assigned CVE-2026-82607 and is rated as high severity. WordPress site administrators running affected versions are strongly advised to upgrade to version 3.16.2, which resolves the issue. No workaround is documented other than upgrading the plugin.