ProfilePress Paid Membership Plugin
cpe:2.3:a:profilepress:user_registration,_login_form,_user_profile_&_membership:*:*:*:*:wordpress:*:*
- <= 4.16.11
A vulnerability exists in the ProfilePress WordPress plugin, specifically in the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile, and Restrict Content components, all versions through 4.16.11. The issue allows for arbitrary shortcode execution. This vulnerability arises because the plugin improperly sanitizes user-supplied billing information from the checkout process, allowing unauthenticated users to execute custom shortcodes by submitting crafted billing values. The vulnerability has been patched in version 4.16.12.
Exploitation of this vulnerability allows for arbitrary shortcode execution, which could lead to various impacts depending on the executed shortcode.
Users are advised to update the ProfilePress WordPress plugin to version 4.16.12 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.