{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/paid-membership-plugin-ecommerce-user-registration-form-login-form-user-profile--restrict-content--profilepress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:profilepress:profilepress:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-92536"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile \u0026 Restrict Content – ProfilePress"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","wordpress","cve"],"_cs_type":"advisory","_cs_vendors":["ProfilePress"],"content_html":"\u003cp\u003eThe ProfilePress plugin for WordPress, a membership and user profile management tool, contains a critical vulnerability (CVE-2026-92536) in versions up to 4.17.4. The flaw exists within the Member Directory feature and the plugin's registration handler, specifically involving improper handling of shortcode parameters such as [pp-custom-html].\u003c/p\u003e\n\u003cp\u003eAuthenticated attackers with subscriber-level access can manipulate the get_user_profile_structure by injecting base64-encoded payloads that utilize shortcode tags like [profile-email], [profile-username], and [profile-date-registered]. This allows for the exfiltration of sensitive user data including email addresses, login names, and registration timestamps. Furthermore, if the WordPress installation has the 'users_can_register' setting enabled, the plugin fails to enforce nonce validation on the registration handler, enabling unauthenticated attackers to trigger the same data extraction via the reg_nickname and reg_bio fields. This vulnerability poses a significant risk to user privacy and platform integrity.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-92536 leads to unauthorized access to Personally Identifiable Information (PII) of registered WordPress users. Exposed data includes email addresses, usernames, and registration dates. In environments where WordPress site registration is open to the public, the vulnerability is accessible to unauthenticated attackers, dramatically increasing the potential for mass data harvesting. This could facilitate downstream attacks such as targeted phishing, account takeover, or credential stuffing using the gathered PII.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to secure vulnerable WordPress installations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the ProfilePress plugin to the latest version patched against CVE-2026-92536.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous POST requests to the WordPress registration handler that contain encoded payloads or unexpected query parameters in the reg_nickname and reg_bio fields.\u003c/li\u003e\n\u003cli\u003eIf an update is not immediately feasible, disable the registration functionality in WordPress settings (users_can_register) to mitigate unauthenticated exploitation.\u003c/li\u003e\n\u003cli\u003eReview all pages and posts for usage of the [pp-custom-html] shortcode to identify potentially malicious or unauthorized injections.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T04:53:26Z","date_published":"2026-10-03T04:53:26Z","id":"https://feed.craftedsignal.io/briefs/2026-10-profilepress-info-exposure/","summary":"The ProfilePress plugin for WordPress (\u003c= 4.17.4) is vulnerable to sensitive information exposure, allowing authenticated and unauthenticated attackers to extract user PII via crafted shortcode parameters.","title":"Sensitive Information Exposure in ProfilePress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-profilepress-info-exposure/"}],"language":"en","title":"CraftedSignal Threat Feed - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile \u0026 Restrict Content – ProfilePress","version":"https://jsonfeed.org/version/1.1"}