← العودة للجدول
CVE-2026-92536
CVE-2026-92536 — The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
📅 2026-10-03
🟠 High 🔥 No NVD Exploit WordPress CVSS 8.8

📋 الوصف الكامل

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract other users' e

💻 الأنظمة المتأثرة

WordPress

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-92536

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v4.17.4

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←