Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-12497— ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection

Quick assessment

Affected
Unknown Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content是properfraction个人开发者的一款集会员管理、电子商务、用户注册登录、个人资料及内容限制功能的WordPress插件。 WordPress ProfilePress 4.16.18之前版本存在权限许可和访问控制问题漏洞,该漏洞源于角色限制执行不一致且缺少随机数检查

AI Predicted 9.8 Difficulty: Trivial EPSS 0.39% · P31

Affected Version Matrix 1

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12497

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection
Source: CVE Program / CVE List V5
Vulnerability Description
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some valid ways of configuring the offered roles the handler ignores the restriction and falls back to accepting any non-administrator role. Combined with the absence of a nonce on the public registration handler, this allows an unauthenticated visitor to register an account with a higher role, such as Editor or Author, than the form was configured to offer.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress ProfilePress 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content是properfraction个人开发者的一款集会员管理、电子商务、用户注册登录、个人资料及内容限制功能的WordPress插件。 WordPress ProfilePress 4.16.18之前版本存在权限许可和访问控制问题漏洞,该漏洞源于角色限制执行不一致且缺少随机数检查
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

II. Public POCs for CVE-2026-12497

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12497

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-12497 (1)

Same Patch Batch · Unknown · 2026-07-24 · 7 CVEs total

CVE-2026-14603 WowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row Injection
CVE-2026-12688 ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via Pay
CVE-2026-12689 ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tamperi
CVE-2026-12690 ProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Authorization
CVE-2026-12981 CAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password Reset
CVE-2026-12877 Software Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Parameter

IV. Related Vulnerabilities

V. Comments for CVE-2026-12497

No comments yet


Leave a comment