Overview
A high-severity Sensitive Information Exposure vulnerability (CVE-2026-92536, CVSS 8.8) has been disclosed in ProfilePress — the "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content" plugin for WordPress, maintained by properfraction and installed on over 100,000 sites. The flaw lives in the plugin's get_user_profile_structure function and allows attackers to extract other users' email addresses, login usernames, and account registration dates by injecting manipulated shortcode payloads into profile fields.
The issue affects all ProfilePress versions up to and including 4.17.4 and was assigned by Wordfence, which credits the vendor with notification on September 16, 2026 and public disclosure on October 2, 2026. A fix shipped in version 4.17.5; the current release at the time of publication is 4.17.6.
Vulnerability Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-92536 |
| Plugin | ProfilePress (Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content) |
| Vendor | properfraction |
| Affected Versions | ≤ 4.17.4 |
| Patched Version | 4.17.5 (latest: 4.17.6) |
| CVSS Score | 8.8 (High) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Weakness | CWE-200 (Sensitive Information Exposure); related CWE-94 (Code Injection) classification also cited |
| Privileges Required | Subscriber-level authentication (low); unauthenticated when users_can_register is enabled |
| Vulnerable Function | get_user_profile_structure |
| Assigner | Wordfence |
| Disclosure Date | October 2–3, 2026 |
| Active Installations | 100,000+ |
How It Works
The Vulnerable Function
get_user_profile_structure handles data retrieval for ProfilePress's profile-rendering shortcodes. The function is intended to restrict which fields a given shortcode can pull and for which user, but it fails to properly validate or sanitize shortcode input when processing custom HTML blocks — specifically the [pp-custom-html] shortcode.
Authenticated Attack Path — Member Directory Abuse
An attacker with Subscriber-level access or higher can abuse the plugin's Member Directory feature, which renders a per-row listing of site users. By embedding an attacker-controlled, base64-encoded payload inside a [pp-custom-html] shortcode, the attacker can manipulate the per-row "user rebinding" mechanism that the directory uses to populate each row. This lets the attacker rebind nested shortcodes such as [profile-email], [profile-username], and [profile-date-registered] to pull data belonging to other users instead of the data normally scoped to the directory context — exfiltrating email addresses, login names, and registration timestamps for the entire member base.
Unauthenticated Attack Path — Open Registration Abuse
Where the WordPress option users_can_register is enabled, the vulnerability becomes reachable without any authentication at all. ProfilePress's own registration handler processes the reg_nickname and reg_bio fields without enforcing a nonce check. An unauthenticated visitor can submit the split shortcode fragments through these registration fields, achieving the same information disclosure that would otherwise require a Subscriber account.
Nonce Weakness
Compounding the issue, the nonce required to trigger the vulnerable action is emitted on every WordPress admin page — including /wp-admin/profile.php, which is accessible to Subscribers. This makes the nonce trivially obtainable by any authenticated user, removing what would otherwise be a meaningful barrier for the Member Directory attack path.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Exposure of other users' email addresses, usernames, and registration dates across the full member base |
| Credential Stuffing / Phishing | Harvested emails and usernames enable targeted phishing and credential-stuffing campaigns against site members |
| Privacy / Compliance | Bulk extraction of personal data may trigger breach-notification obligations under GDPR, PIPEDA, or similar regimes depending on jurisdiction and site user base |
| Attack Surface | Low barrier to entry — open registration (common on membership and e-commerce sites) allows fully unauthenticated exploitation |
| Detection Difficulty | Payloads are base64-encoded and delivered through normal-looking registration or profile-update requests, making casual log review ineffective |
| Scope | Limited to data exposed within the WordPress installation, but harvested identifiers can support follow-on attacks (account takeover attempts, spear-phishing) outside the site |
Sites most at risk are those running ProfilePress for membership management, e-commerce checkout, or public-facing member directories, particularly where self-registration is open to the public.
Recommendations
For Site Administrators
- Update ProfilePress to version 4.17.5 or later immediately (current release: 4.17.6).
wp plugin update profilepress wp plugin get profilepress --field=version - If immediate patching is not possible, disable public registration (
Settings > General > Membership > Anyone can register) to close the unauthenticated attack path. - Disable or restrict the Member Directory feature until the plugin is patched, if the directory is not business-critical.
- Audit recent user registrations and profile edits for unusual base64-encoded content in nickname or biography fields.
For Security Teams
- Review web server and application logs for repeated or automated requests to registration endpoints and Member Directory pages.
- Search the
wp_usermetaandwp_userstables for nickname/bio fields containing encoded shortcode fragments (e.g. base64 blobs referencingpp-custom-html,profile-email,profile-username, orprofile-date-registered). - Treat any site with open registration and an outdated ProfilePress install as actively exploitable until patched — this is a low-complexity, network-reachable flaw with no user interaction required.
- Monitor for the related CVE-2026-92551 (reflected XSS via the
ppress_billing_addressfilename parameter), also fixed in 4.17.5, which affects the same plugin and release line.
For Site Members / Users
- If you have an account on a site running ProfilePress, consider that your email address, username, and registration date may have already been exposed — be alert for phishing attempts referencing these details.
- Enable multi-factor authentication wherever the affected site supports it.
- Avoid reusing passwords across sites, since harvested usernames and emails are frequently used to seed credential-stuffing attacks elsewhere.
Key Takeaways
- CVE-2026-92536 (CVSS 8.8) affects the ProfilePress WordPress plugin in all versions ≤ 4.17.4; the fix shipped in 4.17.5.
- The flaw lives in
get_user_profile_structureand is exploited via base64-encoded shortcode payloads inside the[pp-custom-html]shortcode. - The primary path requires only Subscriber-level authentication via the Member Directory; a fully unauthenticated path exists when
users_can_registeris enabled, via thereg_nickname/reg_bioregistration fields. - A weak nonce distribution (emitted on Subscriber-accessible admin pages) undermines the plugin's own CSRF protection for this feature.
- Exposed data includes email addresses, usernames, and registration dates — sufficient to fuel phishing and credential-stuffing campaigns.
- There is no known public exploitation and the CVE is not listed in CISA KEV as of publication, but patching should not be delayed given the low attack complexity and 100,000+ affected installs.