{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aprofilepressprofilepresswordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:profilepress:profilepress:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-66047"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ProfilePress (\u003c 4.17.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ProfilePress"],"content_html":"\u003cp\u003eThe ProfilePress WordPress plugin (formerly wp-user-avatar) versions prior to 4.17.2 are vulnerable to an unauthenticated remote code execution exploit identified as CVE-2026-66047. The vulnerability exists within the ppress_connect_process AJAX handler, which utilizes a weak 32-bit connect token for authentication. Attackers can brute-force this token to bypass authorization and interface with the handler. Once the token is discovered, an attacker can supply a malicious URL via the file request parameter, instructing the server to download and activate a ZIP file containing a WordPress plugin of the attacker's choosing. This process results in arbitrary PHP code execution within the context of the web-server user. This vulnerability is critical for WordPress administrators as it provides a trivial path to full site compromise without requiring any prior authentication.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to achieve arbitrary code execution on the underlying server. This can lead to full site takeover, unauthorized access to sensitive database information, exfiltration of user data, and potential lateral movement within the hosting environment. All WordPress sites running versions of ProfilePress prior to 4.17.2 are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the ProfilePress WordPress plugin to version 4.17.2 or later immediately.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for high-frequency POST requests to the 'admin-ajax.php' endpoint, specifically targeting the 'ppress_connect_process' action, which may indicate a brute-force attempt against the 32-bit connect token.\u003c/li\u003e\n\u003cli\u003eReview installed WordPress plugins for unauthorized additions or suspicious activity originating from the plugin directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T15:58:11Z","date_published":"2026-08-31T15:58:11Z","id":"https://feed.craftedsignal.io/briefs/2026-08-profilepress-rce/","summary":"The ProfilePress WordPress plugin contains an unauthenticated RCE vulnerability (CVE-2026-66047) caused by a predictable 32-bit connect token in the AJAX handler, allowing remote attackers to install malicious plugins.","title":"Unauthenticated Remote Code Execution in ProfilePress WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-profilepress-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:profilepress:profilepress:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}