Description
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.
Published: 2026-09-19
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Code Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability enables an authenticated user with subscriber or higher privileges to inject and execute arbitrary shortcodes via the "eup_bio" biography field. Because the plugin passes unsanitized input straight to do_shortcode, an attacker can run malicious code, embed external scripts, or otherwise alter the WordPress site’s content or behavior, potentially achieving full control of the site.

Affected Systems

The affected product is the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress for WordPress. All releases up to and including version 4.17.2 are vulnerable, affecting any WordPress installation that has this plugin installed and allows subscribers or higher roles to edit the biography field.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this moment. The flaw requires an authenticated user, but numerous WordPress sites provision subscriber accounts, making the attack vector realistic. The vulnerability is not currently listed in the CISA KEV catalog, yet administrators should treat it with urgency due to its potential impact.

Generated by OpenCVE AI on September 19, 2026 at 23:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the ProfilePress plugin to version 4.17.3 or later, which removes the vulnerable shortcode processing.
  • If an immediate update cannot be applied, disable shortcode processing for the "eup_bio" field by modifying the plugin’s code or by using a security plugin to block shortcodes in that field for all but trusted roles.
  • Audit other user‑editable fields on the site to ensure they do not parse shortcodes unless explicitly permitted, and review the site for any residual vulnerable code.

Generated by OpenCVE AI on September 19, 2026 at 23:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Properfraction
Properfraction paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profilepress
Wordpress
Wordpress wordpress
Vendors & Products Properfraction
Properfraction paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profilepress
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.
Title Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket)
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profilepress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:21.938Z

Reserved: 2026-09-04T13:29:07.249Z

Link: CVE-2026-85658

cve-icon Vulnrichment

Updated: 2026-09-19T13:51:30.442Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:54.770

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-85658

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')