CVE-2026-19848 | ProfilePress Plugin up to 4.17.0 on WordPress Shortcode injection

SecurityVulns

A vulnerability identified as critical has been detected in ProfilePress Plugin up to 4.17.0 on WordPress. This impacts an unknown function of the component Shortcode Handler. Performing a manipulation results in injection.

This vulnerability is known as CVE-2026-19848. Remote exploitation of the attack is possible. No exploit is available.

You should upgrade the affected component.VulDB Recent EntriesRead More