• PATCH AVAILABLE

CVE-2026-66047: pre-auth remote code execution in Proper Fraction ProfilePress

An unauthenticated attacker can run PHP code on a WordPress site using a vulnerability in the ProfilePress plugin (CVE-2026-66047). The issue arises from a weak 32-bit connection token handled by the plugin's ppress_connect_process AJAX endpoint, allowing an attacker to supply a crafted file URL and trigger automatic download and activation of a plugin which leads to code execution as the web server user. The flaw affects ProfilePress 4.x releases before 4.17.2. The attacker only needs network access to a site running the vulnerable plugin; no account or user interaction is required.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
8.1HIGH
EPSS
0.00924
CWE
CWE-306
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

High urgency: this is an unauthenticated RCE that allows code execution without credentials, so immediately update internet-facing ProfilePress instances to 4.17.2.

What is CVE-2026-66047?

An unauthenticated attacker can run PHP code on a WordPress site using a vulnerability in the ProfilePress plugin (CVE-2026-66047). The issue arises from a weak 32-bit connection token handled by the plugin's ppress_connect_process AJAX endpoint, allowing an attacker to supply a crafted file URL and trigger automatic download and activation of a plugin which leads to code execution as the web server user. The flaw affects ProfilePress 4.x releases before 4.17.2. The attacker only needs network access to a site running the vulnerable plugin; no account or user interaction is required. The weakness is classified as CWE-306 (Missing Authentication for Critical Function).

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Proper Fraction ProfilePress are affected?

BRANCHAFFECTEDFIXED
4.xbefore 4.17.24.17.2

Is CVE-2026-66047 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-66047

  1. Upgrade ProfilePress 4.x to 4.17.2 immediately.
  2. If patching is delayed, restrict access to the ppress_connect_process AJAX handler with network controls or a WAF rule.
  3. Scan for unexpected plugin installations and web-writeable backdoors and review recent admin-ajax.php activity in logs.

Frequently asked questions

Is CVE-2026-66047 being actively exploited?

There are no public reports of active exploitation of CVE-2026-66047 as of 2026-09-30.

Which ProfilePress versions are affected by CVE-2026-66047?

ProfilePress 4.x releases before 4.17.2 are affected by CVE-2026-66047.

Is there a patch for CVE-2026-66047?

Yes. Proper Fraction released a fix in ProfilePress version 4.17.2; update to that version.

Does CVE-2026-66047 require authentication?

No. The vulnerability can be exploited without an account or user interaction.

References