CVE-2026-18385

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.19 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.19. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes. The partial mitigation introduced via strip_shortcodes() on [profile-first-name] and [profile-last-name] can be bypassed through the [profile-display-name format="first_last_names"] render path, the [profile-bio] render path (which re-fetches the raw description meta), and the double-bracket escape sequence [[tag]], all of which allow attacker-controlled shortcode text to reach the outer do_shortcode() call.


We have discovered 43,049 live websites that are affected by CVE-2026-18385.

Run a Free Instant Scan




Affected Software

Product  ProfilePress
Category Wordpress Plugins
Vulnerable Domains43,049 live websites (100% of ProfilePress install base)
Vulnerable Versions
  • from 0 through 4.16.19
Vulnerable Versions Count131 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • stealthcopter (finder)
  • Kishan Vyas (finder)

Website Distribution by Country

Number of websites using CVE-2026-18385
United States14,304 websites



Japan4,911 websites
Germany4,193 websites
France2,179 websites
Italy1,727 websites
GB1,583 websites
Spain1,085 websites
Brazil1,076 websites
Netherlands953 websites
Poland904 websites

Website Distribution by TLD

Number of websites using CVE-2026-18385
.com20,063 websites
.de2,354 websites
.org2,335 websites
.net1,530 websites
.it1,331 websites
.com.br1,007 websites
.jp875 websites
.nl838 websites
.co.uk817 websites
.fr769 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18385

Top websites that are affected by CVE-2026-18385. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com France*,***
********.com United States*,***
********.com United States*,***
*********.com United States*,***
*******.com Canada*,***
*********.com United States*,***
************.org United States*,***
*******.com United States*,***
******.com United States*,***
**********.com United States**,***
See full domain list

FAQ

CVE-2026-18385 is Improper Control of Generation of Code ('Code Injection') in ProfilePress
A total of 43,049 websites have been identified as vulnerable to CVE-2026-18385, based on global website indexing conducted by WebTechSurvey.
The ProfilePress is affected by the CVE-2026-18385 vulnerability.
ProfilePress versions up to and including 4.16.19 are vulnerable to CVE-2026-18385.

References