PT-2026-30346 · WordPress · Profilepress

Nabil Irawan

·

Published

2026-04-04

·

Updated

2026-04-04

·

CVE-2026-3309

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ProfilePress versions through 4.16.11
Description The ProfilePress plugin for WordPress is susceptible to arbitrary shortcode execution. This occurs because the plugin doesn't properly sanitize user-supplied billing field values during the checkout process before using them in shortcode template strings. This allows unauthenticated attackers to execute arbitrary shortcodes by submitting crafted billing field values.
Recommendations Update to a version beyond 4.16.11

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-3309

Affected Products

Profilepress