Description
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is exploitable via any page hosting the ProfilePress Tabbed Widget by supplying a malicious filename for the ppress_billing_address file upload field in a crafted POST request.
Published: 2026-10-03
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side Script Injection via Reflected XSS
Action: Patch Immediately
AI Analysis

Impact

The ProfilePress plugin includes a reflected cross‑site scripting flaw triggered by the ppress_billing_address filename parameter. Unsanitized input in a POST request allows an attacker to embed arbitrary scripts that the victim’s browser will execute when they click a crafted link, leading to potential defacement, phishing, or session hijacking.

Affected Systems

All WordPress sites that have the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress installed in versions 4.17.4 or earlier are susceptible. The vulnerability is specific to pages hosting the ProfilePress Tabbed Widget where the file upload field is present.

Risk and Exploitability

The severity is moderate with a CVSS score of 6.1. No exploit probability data is available from EPSS and the flaw is not listed in the CISA KEV catalog. The attack requires no authentication and can be carried out by a malicious link that the victim clicks; if the user is not prevented from visiting such a link, the malicious script will run in their browser session. Because the vector is user interaction based, the exploitability is limited to social engineering or phishing, but the impact on the compromised user can be significant.

Generated by OpenCVE AI on October 3, 2026 at 04:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the ProfilePress plugin to the latest release that removes the vulnerability
  • If an immediate update is not possible, disable the ProfilePress Tabbed Widget or block the ppress_billing_address parameter from accepting values
  • Add input validation or sanitization to the file upload handler so that the filename is strictly checked and escaped before being reflected back in the page

Generated by OpenCVE AI on October 3, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is exploitable via any page hosting the ProfilePress Tabbed Widget by supplying a malicious filename for the ppress_billing_address file upload field in a crafted POST request.
Title Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:46.672Z

Reserved: 2026-09-16T13:09:36.230Z

Link: CVE-2026-92551

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:41.691Z

cve-icon NVD

Status : Received

Published: 2026-10-03T04:18:03.183

Modified: 2026-10-03T16:16:43.203

Link: CVE-2026-92551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T04:30:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')