DIRAS TAKE
High urgency: this is an unauthenticated RCE that allows code execution without credentials, so immediately update internet-facing ProfilePress instances to 4.17.2.
What is CVE-2026-66047?
An unauthenticated attacker can run PHP code on a WordPress site using a vulnerability in the ProfilePress plugin (CVE-2026-66047). The issue arises from a weak 32-bit connection token handled by the plugin's ppress_connect_process AJAX endpoint, allowing an attacker to supply a crafted file URL and trigger automatic download and activation of a plugin which leads to code execution as the web server user. The flaw affects ProfilePress 4.x releases before 4.17.2. The attacker only needs network access to a site running the vulnerable plugin; no account or user interaction is required. The weakness is classified as CWE-306 (Missing Authentication for Critical Function).
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Proper Fraction ProfilePress are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 4.x | before 4.17.2 | 4.17.2 |
Is CVE-2026-66047 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-66047
- Upgrade ProfilePress 4.x to 4.17.2 immediately.
- If patching is delayed, restrict access to the ppress_connect_process AJAX handler with network controls or a WAF rule.
- Scan for unexpected plugin installations and web-writeable backdoors and review recent admin-ajax.php activity in logs.
Frequently asked questions
Is CVE-2026-66047 being actively exploited?
There are no public reports of active exploitation of CVE-2026-66047 as of 2026-09-30.
Which ProfilePress versions are affected by CVE-2026-66047?
ProfilePress 4.x releases before 4.17.2 are affected by CVE-2026-66047.
Is there a patch for CVE-2026-66047?
Yes. Proper Fraction released a fix in ProfilePress version 4.17.2; update to that version.
Does CVE-2026-66047 require authentication?
No. The vulnerability can be exploited without an account or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-66047
- cve.org/CVERecord?id=CVE-2026-66047
- profilepress.com/changelog
- wordpress.org/plugins/wp-user-avatar
- vulncheck.com/advisories/profilepress-wordpress-plugin-unauthenticated-arbitrary-plugin-installation-rce
- All Proper Fraction CVEs on CVE Radar
- CVEs published in September 2026