PT-2026-30316 · WordPress · Profilepress

Supakiad S

·

Published

2026-04-04

·

Updated

2026-04-05

·

CVE-2026-3445

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions ProfilePress versions prior to 4.16.12
Description The ProfilePress plugin for WordPress is susceptible to unauthorized membership payment bypass due to a missing ownership verification on the change plan sub id parameter within the process checkout() function. Authenticated attackers with subscriber-level access or higher can manipulate proration calculations by referencing another user's active subscription during checkout via the ppress process checkout AJAX action, potentially obtaining paid lifetime membership plans without payment.
Recommendations Update ProfilePress to version 4.16.12 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-3445

Affected Products

Profilepress