CVE-2026-19848 | ProfilePress Plugin up to 4.17.0 on WordPress Shortcode injection
A vulnerability identified as critical has been detected in ProfilePress Plugin up to 4.17.0 on WordPress. This impacts an unknown function of the component Shortcode Handler. Performing a manipulation results in injection.
This vulnerability is known as CVE-2026-19848. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More