CVE-2026-13352 | ProfilePress Plugin up to 4.16.18 on WordPress File Upload allowed_mime_types unrestricted upload
A vulnerability was found in ProfilePress Plugin up to 4.16.18 on WordPress. It has been declared as critical. Affected by this vulnerability is the function allowed_mime_types of the component File Upload Handler. Such manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2026-13352. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More