Remote Code Execution Vulnerability in ProfilePress WordPress Plugin by ProfilePress
CVE-2026-66047
9.2CRITICAL
What is CVE-2026-66047?
An unauthenticated remote code execution vulnerability exists in the ProfilePress (wp-user-avatar) WordPress plugin prior to version 4.17.2. This flaw allows attackers to execute arbitrary PHP code on the server by leveraging a weak 32-bit connect token in conjunction with the ppress_connect_process AJAX handler. By crafting malicious requests, an attacker can initiate silent installations of arbitrary plugins, compromising the integrity of the web server and potentially gaining control over user data. Website owners using this plugin are advised to upgrade to the latest version to mitigate the risk.
Affected Version(s)
ProfilePress 0