Arbitrary Shortcode Execution Vulnerability in ProfilePress Plugin for WordPress
CVE-2026-18385

5.4MEDIUM

What is CVE-2026-18385?

The ProfilePress plugin for WordPress is susceptible to arbitrary shortcode execution, allowing authenticated users, including those with subscriber-level access, to execute arbitrary shortcodes. This vulnerability arises from the plugin's failure to adequately validate user inputs before executing the 'do_shortcode' function. While a partial mitigation had been implemented, it can still be bypassed using specific render paths and sequences, leading to the potential exposure of sensitive data or unauthorized actions within the affected systems.

Affected Version(s)

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 0 <= 4.16.19

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

stealthcopter
Kishan Vyas
.