Arbitrary Shortcode Execution in ProfilePress Plugin for WordPress
CVE-2025-13642

5.4MEDIUM

What is CVE-2025-13642?

The ProfilePress plugin for WordPress contains a vulnerability that allows authenticated attackers with Subscriber-level access and higher to execute arbitrary shortcodes. This is due to a lack of adequate input sanitization in the type parameter used within the form preview functionality. This weakness is present in all versions up to and including 4.16.7, exposing sites to potential unauthorized actions through the pp_preview_form endpoint.

Affected Version(s)

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress * <= 4.16.7

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ngoc Quang Bach
.