Shortcode Execution Vulnerability in ProfilePress Plugin for WordPress
CVE-2026-19848
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 21 August 2026
Badges
What is CVE-2026-19848?
The ProfilePress plugin for WordPress, prior to version 4.17.1, is susceptible to a vulnerability that fails to adequately sanitize input in profile fields before rendering. This flaw enables unauthenticated attackers to inject shortcodes, which are executed when the affected profile page is viewed. As a result, sensitive information, including a user's email address and login registration date, can be disclosed, posing significant privacy risks to users.
Affected Version(s)
ProfilePress 0 < 4.17.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved