Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Properfraction
Properfraction profilepress Wordpress Wordpress wordpress |
|
| Vendors & Products |
Properfraction
Properfraction profilepress Wordpress Wordpress wordpress |
Mon, 31 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a caller-controlled URL through the file request parameter to trigger silent plugin installation and activation, achieving PHP code execution as the web-server user. | |
| Title | ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE | |
| Weaknesses | CWE-306 CWE-330 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T14:46:41.174Z
Reserved: 2026-07-23T20:45:17.817Z
Link: CVE-2026-66047
No data.
Status : Received
Published: 2026-08-31T15:17:37.503
Modified: 2026-08-31T15:17:37.503
Link: CVE-2026-66047
No data.
OpenCVE Enrichment
Updated: 2026-08-31T17:15:03Z