CVE-2026-3453Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to missing ownership validation on the change_plan_sub_id parameter in the process_checkout() function. The ppress_process_checkout AJAX handler accepts a user-controlled subscription ID intended for plan upgrades, loads the subscription record, and cancels/expires it without verifying the subscription belongs to the requesting user. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel and expire any other user's active subscription via the change_plan_sub_id parameter during checkout, causing immediate loss of paid access for victims.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-11: 2Technical Details · 2026-03-11: 203-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3453 - High The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to missing ownership validation on the change... https://www.thehackerwire.com/vulnerability/CVE-2026-3453/ https://t.co/h0q60UsZVj

    Post summary

    The message announces a new CVE (2026‑3453) affecting ProfilePress with an IDOR flaw due to missing ownership validation; no PoC, exploit, or patch is mentioned.

    0000045
    134 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3453 The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to missing ownership … https://www.cve.org/CVERecord?id=CVE-2026-3453

    Post summary

    The post announces an Insecure Direct Object Reference flaw in ProfilePress plugin (versions up to 4.16.11) with no evidence of exploitation or remediation.

    0000092
    56.7K followersView on X

Explore more