Impact
The ProfilePress plugin for WordPress contains a flaw that allows attacker‑controlled shortcodes to be injected into user profile fields such as nickname and biographical information. When a subscriber or higher‑privileged user submits a payload that includes a [pp-custom-html] shortcode, the plugin’s internal parser processes embedded tags like [profile-email], [profile-username], and [profile-date-registered] without proper validation. An attacker can therefore trigger the plugin to reveal the email address, login name, and registration date of any site user whose profile row is rendered in the Member Directory. The direct consequence is the exposure of personally identifiable information, compromising confidentiality for all site members.
Affected Systems
This weakness affects the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress, versions up to and including 4.17.4. The vulnerability is present in the core classes EditUserProfile, RegistrationAuth, GlobalFunctions, and the various shortcode parsing modules, which together power the plugin’s user registration and directory features.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score is currently unavailable, but the lack of a concealment factor and the straightforward method of injecting the payload suggest a realistic exploitation probability. The plugin is not listed in CISA’s KEV catalog, but authenticated subscribers can trigger the vulnerability via the Member Directory, and unauthenticated users can trigger it if the WordPress option users_can_register is enabled. Attackers do not need elevated privileges beyond the Subscriber role, making this vulnerability widely exploitable within a compromised site.
OpenCVE Enrichment