CVE-2026-13352: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowedmimetypes function. This is due to the unconditional registration of an uploadmimes filter that adds executable file extensions (.exe, .apk, .msi) to the global WordPress MIME allowlist, without scoping the expansion to digital-product upload contexts. This makes it possible for authenticated attackers, with author-level access and above, to upload files that may be executable, which makes remote code execution possible. This filter is registered globally on every request regardless of whether the digital products feature is configured or in use, meaning the expanded MIME allowlist affects all WordPress upload contexts site-wide.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress ProfilePress plugin (Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content)to a version that resolves this vulnerability.Fixed in 4.16.18 - Compensating control
Restrict authenticated upload capability for Author and above users (e.g., limit roles/permissions and control who can access upload functionality) to reduce the risk of arbitrary file upload leading to remote code execution.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13352?
CVE-2026-13352 has a high severity rating of 8.8.
What is the risk associated with CVE-2026-13352?
The risk level for CVE-2026-13352 is rated at 79.
How do I fix CVE-2026-13352?
To mitigate CVE-2026-13352, upgrade to the latest version of the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content.
What kind of vulnerability is CVE-2026-13352?
CVE-2026-13352 is an arbitrary file upload vulnerability due to unsafe file upload handling.
Who is affected by CVE-2026-13352?
All versions of the ProfilePress Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content up to and including 4.16.18 are affected by CVE-2026-13352.