Description
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract other users' email addresses, login names, and registration dates via the Member Directory's per-row user rebinding when attacker-controlled base64 payloads in the [pp-custom-html] shortcode invoke [profile-email], [profile-username], and [profile-date-registered]. When the WordPress users_can_register option is enabled, unauthenticated attackers can also exploit this vulnerability by supplying the split shortcode fragments through the plugin's own registration handler, which processes the reg_nickname and reg_bio fields without a nonce requirement.
Published: 2026-10-03
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Exposure
Action: Apply Patch
AI Analysis

Impact

The ProfilePress plugin for WordPress contains a flaw that allows attacker‑controlled shortcodes to be injected into user profile fields such as nickname and biographical information. When a subscriber or higher‑privileged user submits a payload that includes a [pp-custom-html] shortcode, the plugin’s internal parser processes embedded tags like [profile-email], [profile-username], and [profile-date-registered] without proper validation. An attacker can therefore trigger the plugin to reveal the email address, login name, and registration date of any site user whose profile row is rendered in the Member Directory. The direct consequence is the exposure of personally identifiable information, compromising confidentiality for all site members.

Affected Systems

This weakness affects the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress, versions up to and including 4.17.4. The vulnerability is present in the core classes EditUserProfile, RegistrationAuth, GlobalFunctions, and the various shortcode parsing modules, which together power the plugin’s user registration and directory features.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and the EPSS score is currently unavailable, but the lack of a concealment factor and the straightforward method of injecting the payload suggest a realistic exploitation probability. The plugin is not listed in CISA’s KEV catalog, but authenticated subscribers can trigger the vulnerability via the Member Directory, and unauthenticated users can trigger it if the WordPress option users_can_register is enabled. Attackers do not need elevated privileges beyond the Subscriber role, making this vulnerability widely exploitable within a compromised site.

Generated by OpenCVE AI on October 3, 2026 at 04:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the ProfilePress plugin to the latest released version, which addresses the shortcode injection vulnerability.
  • If an update is not immediately possible, remove or disable the [pp-custom-html] shortcode processing from the plugin’s registration handler and profile rendering functions, or replace it with a hard‑coded safe rendering method.
  • Sanitize and validate all user‑supplied fields such as reg_nickname and reg_bio by enforcing a nonce check or applying WordPress sanitization functions like wp_kses before storing or rendering them.

Generated by OpenCVE AI on October 3, 2026 at 04:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract other users' email addresses, login names, and registration dates via the Member Directory's per-row user rebinding when attacker-controlled base64 payloads in the [pp-custom-html] shortcode invoke [profile-email], [profile-username], and [profile-date-registered]. When the WordPress users_can_register option is enabled, unauthenticated attackers can also exploit this vulnerability by supplying the split shortcode fragments through the plugin's own registration handler, which processes the reg_nickname and reg_bio fields without a nonce requirement.
Title Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:46.795Z

Reserved: 2026-09-16T12:52:28.435Z

Link: CVE-2026-92536

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:43.259Z

cve-icon NVD

Status : Received

Published: 2026-10-03T04:18:01.853

Modified: 2026-10-03T16:16:42.860

Link: CVE-2026-92536

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T05:00:14Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')