CVE-2026-19848
Received Received - Intake

Stored XSS in ProfilePress WordPress Plugin

Vulnerability report for CVE-2026-19848, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: WPScan

Description

The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allowing unauthenticated attackers to store shortcodes that are then executed when the page is viewed, disclosing a chosen user's email address, login and registration date.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
profilepress profilepress to 4.17.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The ProfilePress WordPress plugin before version 4.17.1 has a flaw where it does not remove shortcodes from two profile fields before displaying them on public pages. This allows attackers to inject shortcodes that execute when the page is viewed, potentially revealing sensitive user data like email addresses, login times, and registration dates.

Detection Guidance

Check if your ProfilePress plugin version is below 4.17.1. Inspect public pages for user profile fields that may render shortcodes. Look for unexpected email addresses, login dates, or registration dates displayed on pages.

Impact Analysis

Unauthenticated attackers could exploit this to access private user information such as email addresses, login credentials, and registration dates by injecting malicious shortcodes into profile fields. This could lead to privacy breaches or identity theft.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data without consent and HIPAA by leaking protected health information if user emails or registration details are tied to such data. Non-compliance may result in legal penalties.

Mitigation Strategies

Update the ProfilePress plugin to version 4.17.1 or later immediately. If updating is not possible, disable the affected profile fields or restrict public access to user profiles until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19848. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart