Junglewise Threat Intelligence

CVE-2026-13352: ProfilePress arbitrary file upload via global MIME allowlist expansion

CVE-2026-13352 · Severity: high · CVSS 8.8 · Published 2026-07-17

Executive brief

ProfilePress, a popular WordPress plugin used for managing memberships and user profiles, contains a security flaw that allows certain users to upload dangerous file types. By default, the plugin incorrectly expands the list of allowed file uploads to include executable files like .exe and .apk across the entire website. An attacker with basic contributor or author permissions could use this to upload malicious code, potentially taking full control of the website and its data.

Technical details

The vulnerability exists in the allowed_mime_types function within the ProfilePress plugin (versions <= 4.16.18). The plugin unconditionally registers an 'upload_mimes' filter that adds executable extensions such as .exe, .apk, and .msi to the global WordPress allowlist. Because this filter is registered globally on every request and is not scoped to specific digital-product upload contexts, it affects all upload interfaces across the WordPress site. Authenticated attackers with author-level privileges or higher can exploit this to upload executable files, leading to remote code execution (RCE). A patch was introduced in versions following 4.16.18.

Affected products

  • properfraction ProfilePress (formerly WP User Avatar) up to and including 4.16.18

Timeline

  • 2026-07-17: advisory: NVD publication date

References