Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92551— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter

Quick assessment

Affected
properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 ProfilePress 插件(功能包括付费会员管理、电子商务、用户注册表单、登录表单、用户个人资料及内容权限控制)在所有版本(最高至 4.17.4)中存在反射型跨站脚本(XSS)漏洞。该漏洞源于对 文件名参数的输入清理和输出转义不足,导致未认证的攻击者能够向网页中注入任意 Web 脚本。如果攻击者成功诱使用户执行某些操作(例如点击恶意链接),这些脚本便会在用户浏览器中执行。 此漏洞可通过任何托管 ProfilePress 选项卡小部件的页面进行利用:攻击者只需在构造的 POST 请求中,为

CVSS 6.1 · Medium

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92551

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is exploitable via any page hosting the ProfilePress Tabbed Widget by supplying a malicious filename for the ppress_billing_address file upload field in a crafted POST request.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

II. Public POCs for CVE-2026-92551

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92551

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-92551 (3)

Proof of Concept for CVE-2026-92551 (1)

News Coverage for CVE-2026-92551 (1)

Other References for CVE-2026-92551 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92551

No comments yet


Leave a comment