5.4
CVE-2026-18385
- EPSS 0.32%
- Veröffentlicht 16.08.2026 04:24:50
- Zuletzt bearbeitet 20.08.2026 12:48:10
- CVE-Watchlists
- Unerledigt
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.19 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.19 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.19. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes. The partial mitigation introduced via strip_shortcodes() on [profile-first-name] and [profile-last-name] can be bypassed through the [profile-display-name format="first_last_names"] render path, the [profile-bio] render path (which re-fetches the raw description meta), and the double-bracket escape sequence [[tag]], all of which allow attacker-controlled shortcode text to reach the outer do_shortcode() call.
Mögliche Gegenmaßnahme
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Update to version 4.17.0, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerproperfraction
≫
Produkt
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Default Statusunaffected
Version <=
4.16.19
Version
0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Version
*-4.16.19
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.246 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
https://www.wordfence.com/threat-intel/vulnerabilities/id/345f3354-d2cb-4b92-a25d-9551a5992919?source=cve
https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.19/src/ShortcodeParser/MemberDirectoryTag.php#L98
https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.19/src/Themes/DragDrop/MemberDirectoryListing.php#L90
https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.19/src/ShortcodeParser/Builder/FrontendProfileBuilder.php#L286
https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.19/src/Classes/RegistrationAuth.php#L170
https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.15/src/ShortcodeParser/MemberDirectoryTag.php#L98
https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.15/src/Themes/DragDrop/MemberDirectoryListing.php#L90
https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.15/src/ShortcodeParser/Builder/FrontendProfileBuilder.php#L286
https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.16.15/src/Classes/RegistrationAuth.php#L170
https://plugins.trac.wordpress.org/changeset?reponame=&old=3635466%40wp-user-avatar&new=3635466%40wp-user-avatar
https://www.wordfence.com/threat-intel/vulnerabilities/id/345f3354-d2cb-4b92-a25d-9551a5992919