PT-2026-83848 · WordPress · Profilepress

·

CVE-2026-66047

·

Published

2026-08-31

·

Updated

2026-09-02

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProfilePress versions prior to 4.17.2
Description An unauthenticated remote code execution issue exists in the ProfilePress WordPress plugin. Unauthenticated attackers can install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress connect process AJAX handler. By providing a caller-controlled URL through the file request parameter, an attacker can trigger a silent plugin installation and activation, resulting in PHP code execution with the privileges of the web-server user.
Recommendations Update ProfilePress to version 4.17.2 or later.

Fix

RCE

Use of Insufficiently Random Values

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66047

Affected Products

Profilepress