PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92536 properfraction CVE debrief

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure. Authenticated attackers with subscriber-level access and above can extract other users' email addresses, login names, and registration dates via the Member Directory's per-row user rebinding when attacker-controlled base64 payloads in the [pp-custom-html] shortcode invoke [profile-email], [profile-username], and [profile-date-registered].

Vendor
properfraction
Product
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for WordPress installations with the ProfilePress plugin, especially those with user registration and directory features, should assess exposure and prioritize verification and remediation efforts.

Why it matters

CVE-2026-92536 is a Sensitive Information Exposure vulnerability in the ProfilePress plugin for WordPress. Defenders should prioritize verifying exposure, assessing impact, and remediating affected systems, especially those with user registration and directory features.

  • Authenticated attackers can extract sensitive user information
  • Potential for lateral movement and further exploitation
  • Need for verification of affected versions and configurations
  • Priority for updating to a patched version

Technical summary

The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4. The vulnerability allows authenticated attackers to extract other users' email addresses, login names, and registration dates via the Member Directory's per-row user rebinding when attacker-controlled base64 payloads in the [pp-custom-html] shortcode invoke [profile-email], [profile-username], and [profile-date-registered]. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those with user registration and directory features. The CVE record and NVD entry provide details on the vulnerability, but further source-

Defensive priority

Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those with user registration and directory features.

Recommended defensive actions

  • Verify the version of the ProfilePress plugin and update to a patched version if necessary
  • Assess the configuration of the Member Directory and restrict access to sensitive information
  • Monitor user activity and logs for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is confirmed in version 4.17.4 of the ProfilePress plugin. The CVE record and NVD entry provide details on the vulnerability, but further verification is needed to determine the full scope of affected versions and potential impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92536 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92536

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92536 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92536

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Classes/EditUserProfile.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Classes/RegistrationAuth.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Functions/GlobalFunctions.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/ShortcodeParser/Builder/GlobalShortcodes.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/ShortcodeParser/FrontendProfileTag.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/ShortcodeParser/MemberDirectoryTag.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Themes/DragDrop/MemberDirectoryListing.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Themes/DragDrop/ProfileFieldListing.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.