CVE-2026-18385 | ProfilePress Plugin up to 4.16.19 on WordPress Shortcode do_shortcode escape output

SecurityVulns

A vulnerability, which was classified as critical, was found in ProfilePress Plugin up to 4.16.19 on WordPress. This impacts the function do_shortcode of the component Shortcode Handler. The manipulation results in escaping of output.

This vulnerability is reported as CVE-2026-18385. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More