Arbitrary File Upload Vulnerability in ProfilePress Plugin for WordPress
CVE-2026-13352
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 July 2026
What is CVE-2026-13352?
The ProfilePress plugin for WordPress contains a vulnerability allowing arbitrary file uploads in all versions up to 4.16.18. This issue arises from the unconditional registration of an upload_mimes filter, which mistakenly adds executable file types such as .exe, .apk, and .msi to the global MIME types allowlist. As a result, authenticated users with author-level permissions can upload potentially malicious executable files in any upload context across the entire WordPress site, leading to a risk of remote code execution.
Affected Version(s)
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β ProfilePress 0 <= 4.16.18