Remote Code Execution Vulnerability in ProfilePress WordPress Plugin by ProfilePress
CVE-2026-66047

9.2CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
31 August 2026

What is CVE-2026-66047?

An unauthenticated remote code execution vulnerability exists in the ProfilePress (wp-user-avatar) WordPress plugin prior to version 4.17.2. This flaw allows attackers to execute arbitrary PHP code on the server by leveraging a weak 32-bit connect token in conjunction with the ppress_connect_process AJAX handler. By crafting malicious requests, an attacker can initiate silent installations of arbitrary plugins, compromising the integrity of the web server and potentially gaining control over user data. Website owners using this plugin are advised to upgrade to the latest version to mitigate the risk.

Affected Version(s)

ProfilePress 0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jon Bytyqi
Leon Bytyci
VulnCheck
.