The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.19. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes. The partial mitigation introduced via strip_shortcodes() on [profile-first-name] and [profile-last-name] can be bypassed through the [profile-display-name format="first_last_names"] render path, the [profile-bio] render path (which re-fetches the raw description meta), and the double-bracket escape sequence [[tag]], all of which allow attacker-controlled shortcode text to reach the outer do_shortcode() call.
We have discovered 43,049 live websites that are affected by CVE-2026-18385.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 43,049 live websites (100% of ProfilePress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 131 versions ( 100% of all versions) |
| 14,304 websites | |
| 4,911 websites | |
| 4,193 websites | |
| 2,179 websites | |
| 1,727 websites | |
| 1,583 websites | |
| 1,085 websites | |
| 1,076 websites | |
| 953 websites | |
| 904 websites |
| .com | 20,063 websites |
| .de | 2,354 websites |
| .org | 2,335 websites |
| .net | 1,530 websites |
| .it | 1,331 websites |
| .com.br | 1,007 websites |
| .jp | 875 websites |
| .nl | 838 websites |
| .co.uk | 817 websites |
| .fr | 769 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | *,*** | ||
| ********.com | *,*** | ||
| ********.com | *,*** | ||
| *********.com | *,*** | ||
| *******.com | *,*** | ||
| *********.com | *,*** | ||
| ************.org | *,*** | ||
| *******.com | *,*** | ||
| ******.com | *,*** | ||
| **********.com | **,*** |
FAQ