Impact
The vulnerability enables an authenticated user with subscriber or higher privileges to inject and execute arbitrary shortcodes via the "eup_bio" biography field. Because the plugin passes unsanitized input straight to do_shortcode, an attacker can run malicious code, embed external scripts, or otherwise alter the WordPress site’s content or behavior, potentially achieving full control of the site.
Affected Systems
The affected product is the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress for WordPress. All releases up to and including version 4.17.2 are vulnerable, affecting any WordPress installation that has this plugin installed and allows subscribers or higher roles to edit the biography field.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this moment. The flaw requires an authenticated user, but numerous WordPress sites provision subscriber accounts, making the attack vector realistic. The vulnerability is not currently listed in the CISA KEV catalog, yet administrators should treat it with urgency due to its potential impact.
OpenCVE Enrichment