Junglewise Threat Intelligence

CVE-2026-85658: ProfilePress arbitrary shortcode execution

CVE-2026-85658 · Severity: high · CVSS 8.1 · Published 2026-09-19

Technologies: ProfilePress. Vendors: ProfilePress.

Executive brief

ProfilePress is a WordPress plugin that manages user registrations, memberships, and content access. The plugin fails to properly validate user input when processing shortcodes, allowing authenticated attackers with subscriber-level permissions to execute arbitrary shortcodes. This can lead to unauthorized actions, data exposure, or website compromise depending on available shortcodes.

Technical details

The vulnerability exists in the plugin's handling of user-supplied input to the do_shortcode() function without proper sanitization or validation. Authenticated users with subscriber-level access and above can inject and execute arbitrary WordPress shortcodes. The issue affects all versions up to and including 4.17.2, and requires an attacker to be authenticated but does not require elevated privileges beyond subscriber level.

Affected products

  • ProfilePress ProfilePress up to and including 4.17.2

Timeline

  • 2026-09-19: disclosed

References

Related threats