Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields
Summary
| CVE | CVE-2026-92536 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-03 04:18:01 UTC |
| Updated | 2026-10-03 16:16:42 UTC |
| Description | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract other users' email addresses, login names, and registration dates via the Member Directory's per-row user rebinding when attacker-controlled base64 payloads in the [pp-custom-html] shortcode invoke [profile-email], [profile-username], and [profile-date-registered]. When the WordPress users_can_register option is enabled, unauthenticated attackers can also exploit this vulnerability by supplying the split shortcode fragments through the plugin's own registration handler, which processes the reg_nickname and reg_bio fields without a nonce requirement. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-94 | CWE-94 CWE-94 Improper Control of Generation of Code ('Code Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Properfraction | Paid Membership Plugin Ecommerce User Registration Form Login Form User Profile Restrict Content ProfilePress | affected 4.17.4 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Classes/RegistrationAu... | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Themes/DragDrop/Member... | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Themes/DragDrop/Profil... | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/ShortcodeParser/Builde... | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Classes/EditUserProfil... | [email protected] | plugins.trac.wordpress.org | |
| www.wordfence.com/threat-intel/vulnerabilities/id/1340aeb3-12a0-4965-95db-45d75... | [email protected] | www.wordfence.com | |
| plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/ShortcodeParser/Member... | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Functions/GlobalFuncti... | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/ShortcodeParser/Fronte... | [email protected] | plugins.trac.wordpress.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Jakub Herman (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-09-16T13:19:42.000Z | Vendor Notified |
| CNA | 2026-10-02T14:31:10.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.