CVE-2026-85658
8.1ProfilePress · Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
The ProfilePress WordPress plugin is vulnerable to arbitrary shortcode execution in versions up to 4.17.2, allowing authenticated users to inject and execute code via improper shortcode validation.
Executive summary
A critical vulnerability in the ProfilePress WordPress plugin allows authenticated users to execute arbitrary shortcodes, potentially leading to unauthorized data access or modification.
Vulnerability
This is a code injection vulnerability caused by improper input validation when processing shortcodes. The flaw allows any authenticated user with subscriber-level access or higher to trigger arbitrary shortcode execution through the plugin interface.
Business impact
The ability to execute arbitrary shortcodes can lead to significant security compromises, including the unauthorized extraction of sensitive user data, modification of content, or escalation of privileges within the WordPress environment. Given the CVSS score of 8.1, this vulnerability poses a high risk to organizational data integrity and confidentiality. Unauthorized actions performed by attackers could result in severe reputational damage and potential regulatory compliance issues.
Remediation
Immediate Action: Update the ProfilePress plugin to version 4.17.3 or later immediately to resolve the improper input validation.
Proactive Monitoring: Review WordPress access and activity logs for suspicious shortcode usage or anomalous patterns originating from subscriber-level accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) to monitor and block malicious requests containing unexpected or dangerous shortcode patterns directed at the plugin endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The vulnerability represents a high-severity risk that requires immediate attention from IT and security administrators. Organizations utilizing the ProfilePress plugin must prioritize updating to version 4.17.3 to eliminate the injection vector. Failure to apply this patch leaves the application susceptible to exploitation by any registered user on the platform.
More ProfilePress CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Md. Moniruzzaman Prodhan (NomanProdhan), per the CVE Program record.