---
id: CVE-2026-85658
title: >-
  The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form,
  User Profile & Restrict Content – ProfilePress plugin for WordPress is
  vulnerable to arbitrary shortcode execution in all versions up to, and
  including, 4.17.2 Th…
summary: >-
  The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form,
  User Profile & Restrict Content – ProfilePress plugin for WordPress is
  vulnerable to arbitrary shortcode execution in all versions up to, and
  including, 4.17.2 Th…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-94
vendor: properfraction
product: >-
  Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
  Profile & Restrict Content – ProfilePress
affected:
  - >-
    paid_membership_plugin_ecommerce_user_registration_form_login_form_user_profile_restrict_content_profilepress
    <= 4.17.2
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:33:33.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85658'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.2/src/Classes/EditUserProfile.php#L337
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.2/src/Functions/GlobalFunctions.php#L1715
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.2/src/ShortcodeParser/Builder/FrontendProfileBuilder.php#L339
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.2/src/ShortcodeParser/FrontendProfileTag.php#L133
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.2/src/Themes/DragDrop/ProfileFieldListing.php#L146
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3682604/wp-user-avatar/trunk/src/ShortcodeParser/Builder/FrontendProfileBuilder.php
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&new=3682619%40wp-user-avatar%2Ftags%2F4.17.3&old=3666803%40wp-user-avatar%2Ftags%2F4.17.2
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/b8486d1d-8a76-446e-867b-8db32499ebf8?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
epss: 0.00653
epssPercentile: 0.4905
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-19T13:26:03.166997Z'
ingestedAt: '2026-09-19T07:59:56.106Z'
---

## Overview

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
