Arbitrary Shortcode Execution in ProfilePress Plugin for WordPress
CVE-2026-3309
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 April 2026
What is CVE-2026-3309?
The ProfilePress plugin for WordPress is susceptible to a vulnerability that allows arbitrary shortcode execution. This security flaw is present in all versions up to 4.16.11 due to improper handling of user-supplied billing field values during the checkout process. Attackers can exploit this weakness by submitting specially crafted input that gets executed without adequate sanitization of shortcode syntax, enabling unauthorized shortcode commands to run. This could lead to unauthorized access or other malicious activities, emphasizing the need for prompt updates and security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β ProfilePress 0 <= 4.16.11