SECURITYHIGHCVE-2026-92536

CVE-2026-92536: ProfilePress WordPress Plugin Exposes User Data via Shortcode Injection

ProfilePress WordPress plugin versions ≤4.17.4 leak user emails, usernames, and registration dates via shortcode injection (CVSS 8.8). Patch to 4.17.5 now.

Dylan H.

Security Team

October 3, 2026
6 min read
CVE-2026-92536: ProfilePress WordPress Plugin Exposes User Data via Shortcode Injection

Affected Products

  • ProfilePress plugin for WordPress (formerly WP User Avatar), versions ≤ 4.17.4

Overview

A high-severity Sensitive Information Exposure vulnerability (CVE-2026-92536, CVSS 8.8) has been disclosed in ProfilePress — the "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content" plugin for WordPress, maintained by properfraction and installed on over 100,000 sites. The flaw lives in the plugin's get_user_profile_structure function and allows attackers to extract other users' email addresses, login usernames, and account registration dates by injecting manipulated shortcode payloads into profile fields.

The issue affects all ProfilePress versions up to and including 4.17.4 and was assigned by Wordfence, which credits the vendor with notification on September 16, 2026 and public disclosure on October 2, 2026. A fix shipped in version 4.17.5; the current release at the time of publication is 4.17.6.


Vulnerability Details

AttributeValue
CVE IDCVE-2026-92536
PluginProfilePress (Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content)
Vendorproperfraction
Affected Versions≤ 4.17.4
Patched Version4.17.5 (latest: 4.17.6)
CVSS Score8.8 (High)
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
WeaknessCWE-200 (Sensitive Information Exposure); related CWE-94 (Code Injection) classification also cited
Privileges RequiredSubscriber-level authentication (low); unauthenticated when users_can_register is enabled
Vulnerable Functionget_user_profile_structure
AssignerWordfence
Disclosure DateOctober 2–3, 2026
Active Installations100,000+

How It Works

The Vulnerable Function

get_user_profile_structure handles data retrieval for ProfilePress's profile-rendering shortcodes. The function is intended to restrict which fields a given shortcode can pull and for which user, but it fails to properly validate or sanitize shortcode input when processing custom HTML blocks — specifically the [pp-custom-html] shortcode.

Authenticated Attack Path — Member Directory Abuse

An attacker with Subscriber-level access or higher can abuse the plugin's Member Directory feature, which renders a per-row listing of site users. By embedding an attacker-controlled, base64-encoded payload inside a [pp-custom-html] shortcode, the attacker can manipulate the per-row "user rebinding" mechanism that the directory uses to populate each row. This lets the attacker rebind nested shortcodes such as [profile-email], [profile-username], and [profile-date-registered] to pull data belonging to other users instead of the data normally scoped to the directory context — exfiltrating email addresses, login names, and registration timestamps for the entire member base.

Unauthenticated Attack Path — Open Registration Abuse

Where the WordPress option users_can_register is enabled, the vulnerability becomes reachable without any authentication at all. ProfilePress's own registration handler processes the reg_nickname and reg_bio fields without enforcing a nonce check. An unauthenticated visitor can submit the split shortcode fragments through these registration fields, achieving the same information disclosure that would otherwise require a Subscriber account.

Nonce Weakness

Compounding the issue, the nonce required to trigger the vulnerable action is emitted on every WordPress admin page — including /wp-admin/profile.php, which is accessible to Subscribers. This makes the nonce trivially obtainable by any authenticated user, removing what would otherwise be a meaningful barrier for the Member Directory attack path.


Impact Assessment

Impact AreaDescription
ConfidentialityExposure of other users' email addresses, usernames, and registration dates across the full member base
Credential Stuffing / PhishingHarvested emails and usernames enable targeted phishing and credential-stuffing campaigns against site members
Privacy / ComplianceBulk extraction of personal data may trigger breach-notification obligations under GDPR, PIPEDA, or similar regimes depending on jurisdiction and site user base
Attack SurfaceLow barrier to entry — open registration (common on membership and e-commerce sites) allows fully unauthenticated exploitation
Detection DifficultyPayloads are base64-encoded and delivered through normal-looking registration or profile-update requests, making casual log review ineffective
ScopeLimited to data exposed within the WordPress installation, but harvested identifiers can support follow-on attacks (account takeover attempts, spear-phishing) outside the site

Sites most at risk are those running ProfilePress for membership management, e-commerce checkout, or public-facing member directories, particularly where self-registration is open to the public.


Recommendations

For Site Administrators

  1. Update ProfilePress to version 4.17.5 or later immediately (current release: 4.17.6).
    wp plugin update profilepress
    wp plugin get profilepress --field=version
  2. If immediate patching is not possible, disable public registration (Settings > General > Membership > Anyone can register) to close the unauthenticated attack path.
  3. Disable or restrict the Member Directory feature until the plugin is patched, if the directory is not business-critical.
  4. Audit recent user registrations and profile edits for unusual base64-encoded content in nickname or biography fields.

For Security Teams

  1. Review web server and application logs for repeated or automated requests to registration endpoints and Member Directory pages.
  2. Search the wp_usermeta and wp_users tables for nickname/bio fields containing encoded shortcode fragments (e.g. base64 blobs referencing pp-custom-html, profile-email, profile-username, or profile-date-registered).
  3. Treat any site with open registration and an outdated ProfilePress install as actively exploitable until patched — this is a low-complexity, network-reachable flaw with no user interaction required.
  4. Monitor for the related CVE-2026-92551 (reflected XSS via the ppress_billing_address filename parameter), also fixed in 4.17.5, which affects the same plugin and release line.

For Site Members / Users

  1. If you have an account on a site running ProfilePress, consider that your email address, username, and registration date may have already been exposed — be alert for phishing attempts referencing these details.
  2. Enable multi-factor authentication wherever the affected site supports it.
  3. Avoid reusing passwords across sites, since harvested usernames and emails are frequently used to seed credential-stuffing attacks elsewhere.

Key Takeaways

  1. CVE-2026-92536 (CVSS 8.8) affects the ProfilePress WordPress plugin in all versions ≤ 4.17.4; the fix shipped in 4.17.5.
  2. The flaw lives in get_user_profile_structure and is exploited via base64-encoded shortcode payloads inside the [pp-custom-html] shortcode.
  3. The primary path requires only Subscriber-level authentication via the Member Directory; a fully unauthenticated path exists when users_can_register is enabled, via the reg_nickname/reg_bio registration fields.
  4. A weak nonce distribution (emitted on Subscriber-accessible admin pages) undermines the plugin's own CSRF protection for this feature.
  5. Exposed data includes email addresses, usernames, and registration dates — sufficient to fuel phishing and credential-stuffing campaigns.
  6. There is no known public exploitation and the CVE is not listed in CISA KEV as of publication, but patching should not be delayed given the low attack complexity and 100,000+ affected installs.

Sources