CVE-2026-3309Disclosure

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.11. This is due to the plugin allowing user-supplied billing field values from the checkout process to be interpolated into shortcode template strings that are subsequently processed without proper sanitization of shortcode syntax. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes by submitting crafted billing field values during the checkout process.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-04); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-04: 2Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-11: 1Technical Details · 2026-04-04: 104-0404-11
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-042
Disclosure2
2026-04-111
PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-3309-wp-user-avatar-version-4-16-11-medium-vulnerability-proof-of-concept CVE-2026-3309 #WordPress plugin #vulnerability wp-user-avatar #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post announces a proof‑of‑concept for CVE‑2026‑3309 affecting the WordPress wp‑user‑avatar plugin, linking to the PoC via AtomiceEdge.

    0000056
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3309 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrar… https://www.cve.org/CVERecord?id=CVE-2026-3309

    Post summary

    The excerpt announces CVE‑2026‑3309, highlighting that the ProfilePress WordPress plugin is vulnerable, but provides no further details on exploits, patches, or active use.

    00000159
    57.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3309 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Chec… https://ift.tt/CFf7Zsi

    Post summary

    The alert announces CVE-2026-3309 affecting ProfilePress version <=4.16.11, describing an unauthenticated arbitrary shortcode execution vulnerability.

    0000058
    281 followersView on X

Explore more