<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content (&lt;= 4.17.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/paid-membership-plugin-ecommerce-user-registration-form-login-form-user-profile--restrict-content--4.17.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 19 Sep 2026 10:11:19 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/paid-membership-plugin-ecommerce-user-registration-form-login-form-user-profile--restrict-content--4.17.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary Shortcode Execution in ProfilePress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-profilepress-shortcode-exec/</link><pubDate>Sat, 19 Sep 2026 10:11:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-profilepress-shortcode-exec/</guid><description>The ProfilePress WordPress plugin is vulnerable to arbitrary shortcode execution in versions up to 4.17.2, allowing authenticated users with subscriber-level access to execute arbitrary shortcodes.</description><content:encoded><![CDATA[<p>The ProfilePress plugin (formerly known as Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content) for WordPress is affected by an arbitrary shortcode execution vulnerability (CVE-2026-85658). The vulnerability exists in all versions up to and including 4.17.2. The flaw is caused by insufficient validation of user-supplied values before they are processed by the WordPress 'do_shortcode' function. Authenticated attackers with at least subscriber-level permissions can leverage this vulnerability to execute arbitrary shortcodes within the WordPress environment. This can be exploited to access restricted content, potentially escalate privileges depending on the available shortcodes within the installation, or perform other unauthorized actions available to the WordPress shortcode system.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows authenticated users with low-level subscriber access to trigger arbitrary shortcodes. In a WordPress environment, this can lead to unauthorized information disclosure, bypass of content restrictions, or the execution of functional components intended for administrators, effectively increasing the attacker's capabilities beyond their assigned role.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the ProfilePress plugin to the latest available version (beyond 4.17.2) immediately. If an update is not currently possible, restrict access to the registration and profile management pages for unprivileged accounts or disable the plugin until a patch is applied.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>rce</category></item></channel></rss>