Sensitive Information Exposure in ProfilePress Plugin
The ProfilePress plugin for WordPress (<= 4.17.4) is vulnerable to sensitive information exposure, allowing authenticated and unauthenticated attackers to extract user PII via crafted shortcode parameters.
CVE search metadata
CVE search record: CVE-2026-92536. Severity: high. CVSS: 8.8. KEV: no. Product: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress. Brief: Sensitive Information Exposure in ProfilePress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-profilepress-info-exposure/
The ProfilePress plugin for WordPress, a membership and user profile management tool, contains a critical vulnerability (CVE-2026-92536) in versions up to 4.17.4. The flaw exists within the Member Directory feature and the plugin's registration handler, specifically involving improper handling of shortcode parameters such as [pp-custom-html].
Authenticated attackers with subscriber-level access can manipulate the get_user_profile_structure by injecting base64-encoded payloads that utilize shortcode tags like [profile-email], [profile-username], and [profile-date-registered]. This allows for the exfiltration of sensitive user data including email addresses, login names, and registration timestamps. Furthermore, if the WordPress installation has the 'users_can_register' setting enabled, the plugin fails to enforce nonce validation on the registration handler, enabling unauthenticated attackers to trigger the same data extraction via the reg_nickname and reg_bio fields. This vulnerability poses a significant risk to user privacy and platform integrity.
Impact
Successful exploitation of CVE-2026-92536 leads to unauthorized access to Personally Identifiable Information (PII) of registered WordPress users. Exposed data includes email addresses, usernames, and registration dates. In environments where WordPress site registration is open to the public, the vulnerability is accessible to unauthenticated attackers, dramatically increasing the potential for mass data harvesting. This could facilitate downstream attacks such as targeted phishing, account takeover, or credential stuffing using the gathered PII.
Recommendation
Prioritize the following actions to secure vulnerable WordPress installations:
- Immediately update the ProfilePress plugin to the latest version patched against CVE-2026-92536.
- Audit web server access logs for anomalous POST requests to the WordPress registration handler that contain encoded payloads or unexpected query parameters in the reg_nickname and reg_bio fields.
- If an update is not immediately feasible, disable the registration functionality in WordPress settings (users_can_register) to mitigate unauthenticated exploitation.
- Review all pages and posts for usage of the [pp-custom-html] shortcode to identify potentially malicious or unauthorized injections.
Immediate actions
Update ProfilePress plugin to patched version
Mitigations
Disable 'users_can_register' setting in WordPress if patching is delayed
CVE-2026-92536