rootpwn

high · CVSS v3 8.1 · EPSS 0.00361

CVE-2026-85658

The ProfilePress plugin for WordPress contains an arbitrary shortcode execution vulnerability affecting versions up to and including 4.17.2.

Overview

The ProfilePress plugin for WordPress contains an arbitrary shortcode execution vulnerability affecting versions up to and including 4.17.2. The issue occurs because user-supplied input is passed directly to the do_shortcode function without proper validation. This matters because authenticated low-privileged users can leverage this flaw to execute arbitrary shortcodes, potentially triggering unintended functionality within the site.

Description

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.

Impact

This vulnerability impacts the integrity and availability of the WordPress site by allowing authenticated attackers with subscriber-level access to execute arbitrary shortcodes. While confidentiality is generally preserved unless a specific shortcode reveals sensitive data, malicious shortcode execution can lead to site degradation or unauthorized actions. Website administrators and users with low-privileged accounts represent the primary scope of exposure.

Remediation

Update the ProfilePress plugin to the latest version beyond 4.17.2 where input validation for shortcode execution is properly implemented. Restrict unnecessary user registrations or limit account creation to trusted individuals to minimize the risk of low-privileged exploitation. Monitor site error logs and shortcode usage for anomalous activity.

Risk context

The vulnerability carries a CVSS v3 score of 8.1, designating it as high severity due to the potential for unauthorized execution within the application layer. The current EPSS score is 0.00361, indicating a relatively low immediate probability of exploitation in the wild, but patching is still recommended given the ease of authentication.

Affected products

  • ProfilePress WordPress Plugin

Scores

Severity
high
CVSS v2
8.5
CVSS v3
8.1
CVSS v4
EPSS
0.00361

WordPress ProfilePress Shortcode Execution Input Validation Web Application High Severity

← All CVEs