Reflected Cross-Site Scripting in ProfilePress Plugin for WordPress
CVE-2026-92551
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-92551?
The ProfilePress plugin for WordPress is susceptible to Reflected Cross-Site Scripting through the ppress_billing_address parameter due to inadequate input sanitization and output escaping. This vulnerability allows untrusted data to be introduced into web pages, enabling unauthenticated attackers to execute arbitrary scripts in a user's session. Successful exploitation typically requires tricking a user into clicking a malicious link that leads to a crafted POST request, thereby compromising user interactions with the application.
Affected Version(s)
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β ProfilePress 0 <= 4.17.4