CVE-2026-92551: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppressbillingaddress Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is exploitable via any page hosting the ProfilePress Tabbed Widget by supplying a malicious filename for the ppressbillingaddress file upload field in a crafted POST request.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to this issue?
Sites using ProfilePress version 4.17.4 or earlier are exposed where a page hosts the ProfilePress Tabbed Widget. The vulnerable input is the ppress_billing_address file-upload field.
What does an attacker need to exploit it?
An attacker does not need authentication. They need to submit a crafted POST request containing a malicious filename and then successfully induce a user to perform an action such as clicking a link that causes the injected script to execute.
Are visitors affected automatically?
No. Exploitation requires user interaction, such as clicking an attacker-crafted link. The injected script executes in the context of the affected page when that interaction succeeds.