Arbitrary Shortcode Execution Vulnerability in ProfilePress Plugin for WordPress
CVE-2026-18385
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2026-18385?
The ProfilePress plugin for WordPress is susceptible to arbitrary shortcode execution, allowing authenticated users, including those with subscriber-level access, to execute arbitrary shortcodes. This vulnerability arises from the plugin's failure to adequately validate user inputs before executing the 'do_shortcode' function. While a partial mitigation had been implemented, it can still be bypassed using specific render paths and sequences, leading to the potential exposure of sensitive data or unauthorized actions within the affected systems.
Affected Version(s)
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β ProfilePress 0 <= 4.16.19