---
id: CVE-2026-92551
title: >-
  The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form,
  User Profile & Restrict Content – ProfilePress plugin for WordPress is
  vulnerable to Reflected Cross-Site Scripting via ppress_billing_address
  Filename Parameter …
summary: >-
  The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form,
  User Profile & Restrict Content – ProfilePress plugin for WordPress is
  vulnerable to Reflected Cross-Site Scripting via ppress_billing_address
  Filename Parameter …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: properfraction
product: >-
  Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
  Profile & Restrict Content – ProfilePress
affected:
  - >-
    paid_membership_plugin_ecommerce_user_registration_form_login_form_user_profile_restrict_content_profilepress
    <= 4.17.4
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T04:18:03.183'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92551'
references:
  - url: 'https://pastebin.com/raw/AEJW3cKe'
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Classes/FileUploader.php#L24
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Classes/FileUploader.php#L97
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Classes/RegistrationAuth.php#L285
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Widgets/TabbedWidget.php#L108
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Widgets/TabbedWidgetDependency.php#L92
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/269dd459-c857-49ed-b5d6-8c9e946ac590?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T03:38:16.257Z'
---

## Overview

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is exploitable via any page hosting the ProfilePress Tabbed Widget by supplying a malicious filename for the ppress_billing_address file upload field in a crafted POST request.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
