WordPress · Profilepress · CVE-2026-66047
**Name of the Vulnerable Software and Affected Versions**
ProfilePress versions prior to 4.17.2
**Description**
An unauthenticated remote code execution issue exists in the ProfilePress WordPress plugin. Unauthenticated attackers can install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the `ppress connect process` AJAX handler. By providing a caller-controlled URL through the `file request` parameter, an attacker can trigger a silent plugin installation and activation, resulting in PHP code execution with the privileges of the web-server user.
**Recommendations**
Update ProfilePress to version 4.17.2 or later.