← العودة للجدول
CVE-2026-92551
CVE-2026-92551 — The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
📅 2026-10-03
🟡 Medium 🔥 No NVD Exploit WordPress CVSS 6.1

📋 الوصف الكامل

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers

💻 الأنظمة المتأثرة

WordPress

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-92551

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v4.17.4

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←