Vulnerabilidad · Publicado 19/09/2026
El plugin ProfilePress para WordPress (versiones hasta 4.17.2) es vulnerable a ejecución arbitraria de shortcodes por usuarios autenticados debido a validación insuficiente antes de ejecutar do_shortcode. Esta vulnerabilidad afecta sitios de e-commerce, formularios de registro y portales de contenido restringido ampliamente utilizados en LATAM. Un atacante autenticado podría inyectar código malicioso que se ejecute en el contexto del sitio WordPress.
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.
Score: 8.1/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-94
Publicado en NIST NVD.