Junglewise Threat Intelligence

CVE-2026-3445: ProperFraction ProfilePress payment bypass in process_checkout

CVE-2026-3445 · Severity: high · CVSS 7.1 · Published 2026-04-04

Executive brief

ProfilePress, a WordPress plugin used for managing paid memberships and ecommerce checkouts, contains a security flaw that allows users to bypass payment. By exploiting a weakness in how the system calculates subscription changes, an attacker with a basic user account can trick the system into granting them expensive lifetime memberships for free. This could lead to significant revenue loss and unauthorized access to premium content or services.

Technical details

The vulnerability is classified as Missing Authorization (CWE-862) within the `process_checkout()` function of the ProfilePress plugin. The root cause is a lack of ownership verification on the `change_plan_sub_id` parameter. An authenticated attacker with at least Subscriber-level permissions can initiate a checkout via the `ppress_process_checkout` AJAX action and provide a subscription ID belonging to another user. This manipulates the plugin's proration logic, effectively zeroing out the cost and allowing the attacker to acquire premium or lifetime plans for free. The issue is addressed in versions following 4.16.11.

Affected products

  • ProperFraction ProfilePress up to, and including, 4.16.11

Timeline

  • 2026-04-04: advisory: Initial disclosure by Wordfence and NVD published date
  • 2026-04-04: disclosed

References