Junglewise Threat Intelligence

CVE-2026-41556: ProfilePress Cross Site Scripting in WordPress plugin

CVE-2026-41556 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: ProfilePress. Vendors: ProfilePress.

Executive brief

ProfilePress, a popular WordPress plugin used for managing user profiles and memberships, contains a security flaw that allows users with basic 'Subscriber' accounts to inject malicious scripts into the website. If an administrator or another user views the affected area, these scripts could allow an attacker to redirect visitors to malicious sites, display unauthorized advertisements, or potentially hijack user sessions. This vulnerability could be used in automated attacks to compromise a large number of websites simultaneously.

Technical details

ProfilePress (formerly WP User Avatar) versions up to and including 4.16.13 are vulnerable to Stored Cross-Site Scripting (XSS) due to improper input sanitization and output escaping (CWE-79). An authenticated attacker with Subscriber-level privileges can inject malicious web scripts into certain fields. The vulnerability requires a victim (such as an administrator) to interact with the affected page or perform a specific action for the payload to execute. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 4.16.14.

Affected products

  • ProfilePress ProfilePress (formerly WP User Avatar) <= 4.16.13

Timeline

  • 2026-03-28: other: Vulnerability reported by Niv Kochan
  • 2026-04-23: disclosed: Initial disclosure by Patchstack
  • 2026-04-23: patched: Patch released in version 4.16.14
  • 2026-06-15: advisory: NVD publication date

References

Related threats