What is CVE-2026-18385?
CVE-2026-18385 is an arbitrary shortcode execution vulnerability in the ProfilePress plugin for WordPress, affecting versions up to 4.16.19. It allows authenticated users to execute malicious shortcodes. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-18385, WordPress-in ProfilePress pluginində (4.16.19 və əvvəlki versiyalar) ixtiyari shortcode icrası zəifliyidir. Bu, autentifikasiya olunmuş istifadəçilərə təhlükəli shortcode-lər işlətməyə imkan verir. Plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which WordPress plugin is affected by CVE-2026-18385?
CVE-2026-18385 affects the ProfilePress plugin for WordPress.
How to mitigate CVE-2026-18385?
To mitigate CVE-2026-18385, it is recommended to update the ProfilePress plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.