ProfilePress
cpe:2.3:a:profilepress:profilepress:*:*:*:*:wordpress:*:*, +1 more
- <= 4.16.7
A vulnerability allowing arbitrary shortcode execution has been identified in the ProfilePress WordPress plugin, specifically in versions through 4.16.7. This issue arises from inadequate input sanitization on the 'type' parameter within the form preview feature. As a result, authenticated attackers with Subscriber-level access or higher can execute arbitrary shortcodes via the 'pp_preview_form' endpoint.
Exploitation of this vulnerability allows for arbitrary shortcode execution, which could be used to manipulate content or functionality on the WordPress site.
Users are advised to update the ProfilePress WordPress plugin to version 4.16.8 or a later patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.