CVE-2025-13642Medium· 5.4▾ SunlitThe Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.7 du…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.7 due to insufficient input sanitization on the type parameter in the form preview functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes via the pp_preview_form endpoint.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14730Medium· 4.7A security flaw has been discovered in CTCMS Content Management System up to 2.1.2
CVE-2025-14729Medium· 4.7A vulnerability was identified in CTCMS Content Management System up to 2.1.2
CVE-2025-15148Medium· 4.7A flaw has been found in CmsEasy up to 7.7.7
CVE-2025-10097Medium· 6.3A vulnerability was identified in SimStudioAI sim up to 1.0.0
CVE-2025-15394Medium· 4.7A vulnerability was detected in iCMS up to 8.0.0
CVE-2025-15393Medium· 6.3A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135