{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/paid-membership-plugin-ecommerce-user-registration-form-login-form-user-profile--restrict-content--4.17.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:profilepress:paid_membership_plugin,_ecommerce,_user_registration_form,_login_form,_user_profile_\u0026_restrict_content:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-85658"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile \u0026 Restrict Content (\u003c= 4.17.2)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","rce"],"_cs_type":"advisory","_cs_vendors":["ProfilePress"],"content_html":"\u003cp\u003eThe ProfilePress plugin (formerly known as Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile \u0026amp; Restrict Content) for WordPress is affected by an arbitrary shortcode execution vulnerability (CVE-2026-85658). The vulnerability exists in all versions up to and including 4.17.2. The flaw is caused by insufficient validation of user-supplied values before they are processed by the WordPress 'do_shortcode' function. Authenticated attackers with at least subscriber-level permissions can leverage this vulnerability to execute arbitrary shortcodes within the WordPress environment. This can be exploited to access restricted content, potentially escalate privileges depending on the available shortcodes within the installation, or perform other unauthorized actions available to the WordPress shortcode system.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows authenticated users with low-level subscriber access to trigger arbitrary shortcodes. In a WordPress environment, this can lead to unauthorized information disclosure, bypass of content restrictions, or the execution of functional components intended for administrators, effectively increasing the attacker's capabilities beyond their assigned role.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the ProfilePress plugin to the latest available version (beyond 4.17.2) immediately. If an update is not currently possible, restrict access to the registration and profile management pages for unprivileged accounts or disable the plugin until a patch is applied.\u003c/p\u003e\n","date_modified":"2026-09-19T10:11:19Z","date_published":"2026-09-19T10:11:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-profilepress-shortcode-exec/","summary":"The ProfilePress WordPress plugin is vulnerable to arbitrary shortcode execution in versions up to 4.17.2, allowing authenticated users with subscriber-level access to execute arbitrary shortcodes.","title":"Arbitrary Shortcode Execution in ProfilePress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-profilepress-shortcode-exec/"}],"language":"en","title":"CraftedSignal Threat Feed - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile \u0026 Restrict Content (\u003c= 4.17.2)","version":"https://jsonfeed.org/version/1.1"}