Sensitive Information Exposure in ProfilePress Plugin for WordPress
CVE-2026-92536
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-92536?
The ProfilePress plugin for WordPress, impacting all versions up to and including 4.17.4, is susceptible to a sensitive information exposure vulnerability. Authenticated attackers with subscriber-level access can exploit the get_user_profile_structure function to retrieve other users' email addresses, login names, and registration dates. This is achieved via the Member Directory through user rebinding with attacker-controlled base64 payloads embedded in the [pp-custom-html] shortcode, which can invoke [profile-email], [profile-username], and [profile-date-registered]. Additionally, when the WordPress users_can_register option is enabled, unauthenticated attackers can also abuse this vulnerability by leveraging the plugin's registration handler, bypassing nonce requirements to submit unauthorized shortcode fragments.
Affected Version(s)
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β ProfilePress 0 <= 4.17.4