CVE-2026-66047 | ProfilePress Plugin up to 4.17.1 on WordPress AJAX ppress_connect_process File code injection
A vulnerability identified as critical has been detected in ProfilePress Plugin up to 4.17.1 on WordPress. Affected by this issue is the function ppress_connect_process of the component AJAX Handler. The manipulation of the argument File leads to code injection.
This vulnerability is listed as CVE-2026-66047. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More