PatchSiren cyber security CVE debrief
CVE-2026-92536 properfraction CVE debrief
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure. Authenticated attackers with subscriber-level access and above can extract other users' email addresses, login names, and registration dates via the Member Directory's per-row user rebinding when attacker-controlled base64 payloads in the [pp-custom-html] shortcode invoke [profile-email], [profile-username], and [profile-date-registered].
- Vendor
- properfraction
- Product
- Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for WordPress installations with the ProfilePress plugin, especially those with user registration and directory features, should assess exposure and prioritize verification and remediation efforts.
Why it matters
CVE-2026-92536 is a Sensitive Information Exposure vulnerability in the ProfilePress plugin for WordPress. Defenders should prioritize verifying exposure, assessing impact, and remediating affected systems, especially those with user registration and directory features.
- Authenticated attackers can extract sensitive user information
- Potential for lateral movement and further exploitation
- Need for verification of affected versions and configurations
- Priority for updating to a patched version
Technical summary
The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4. The vulnerability allows authenticated attackers to extract other users' email addresses, login names, and registration dates via the Member Directory's per-row user rebinding when attacker-controlled base64 payloads in the [pp-custom-html] shortcode invoke [profile-email], [profile-username], and [profile-date-registered]. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those with user registration and directory features. The CVE record and NVD entry provide details on the vulnerability, but further source-
Defensive priority
Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those with user registration and directory features.
Recommended defensive actions
- Verify the version of the ProfilePress plugin and update to a patched version if necessary
- Assess the configuration of the Member Directory and restrict access to sensitive information
- Monitor user activity and logs for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is confirmed in version 4.17.4 of the ProfilePress plugin. The CVE record and NVD entry provide details on the vulnerability, but further verification is needed to determine the full scope of affected versions and potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92536 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92536
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92536 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92536
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Classes/EditUserProfile.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Classes/RegistrationAuth.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Functions/GlobalFunctions.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/ShortcodeParser/Builder/GlobalShortcodes.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/ShortcodeParser/FrontendProfileTag.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/ShortcodeParser/MemberDirectoryTag.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Themes/DragDrop/MemberDirectoryListing.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-user-avatar/tags/4.17.4/src/Themes/DragDrop/ProfileFieldListing.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.