CRITICAL
Proper Fraction
CVE published 2026-08-31
CVE-2026-66047
CVE-2026-66047 is a critical unauthenticated remote code execution vulnerability in the ProfilePress (wp-user-avatar) WordPress plugin before version 4.17.2. The vulnerability allows attackers to brute-force a weak 32-bit connect token via the ppress_connect_process AJAX handler, leading to the installation and activation of arbitrary plugins and PHP code execution as the web-server user. Defenders should [truncated]