CVE-2026-19848 - ProfilePress < 4.17.1 - Unauthenticated Arbitrary Shortcode Execution via Display Name
CVE ID :CVE-2026-19848
Published : Aug. 21, 2026, 12:16 p.m. | 1 hour, 45 minutes ago
Description :The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allowing unauthenticated attackers to store shortcodes that are then executed when the page is viewed, disclosing a chosen user's email address, login and registration date.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 21, 2026, 12:16 p.m. | 1 hour, 45 minutes ago
Description :The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allowing unauthenticated attackers to store shortcodes that are then executed when the page is viewed, disclosing a chosen user's email address, login and registration date.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...