OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92536

HIGH · CVSS 8.8 EPSS 0.63% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-03 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Paid Membership Plugin for WordPress is vulnerable to sensitive information exposure, allowing authenticated attackers with subscriber-level access and above to extract other users' email addresses, login names, and registration dates. Additionally, if the users_can_register option is enabled, unauthenticated attackers can exploit this vulnerability through the plugin's registration handler, bypassing nonce requirements. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of unauthorized data access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-92536
Severity
HIGH
CVSS
8.8
EPSS
0.63%
WordPress

Original NVD Description

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract other users' email addresses, login names, and registration dates via the Member Directory's per-row user rebinding when attacker-controlled base64 payloads in the [pp-custom-html] shortcode invoke [profile-email], [profile-username], and [profile-date-registered]. When the WordPress users_can_register option is enabled, unauthenticated attackers can also exploit this vulnerability by supplying the split shortcode fragments through the plugin's own registration handler, which processes the reg_nickname and reg_bio fields without a nonce requirement.