天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-92536 ProfilePress 敏感信息泄露漏洞

影响攻击者可获取其他用户的邮箱、登录名和注册日期

AI 研判

WordPress 插件 ProfilePress 在 4.17.4 及之前版本中存在敏感信息泄露漏洞,问题出在 get_user_profile_structure 函数。拥有订阅者及以上权限的认证攻击者可通过 Member Directory 的逐行用户重绑定机制,结合 [pp-custom-html] 短代码中攻击者控制的 base64 载荷,调用 [profile-email]、[profile-username] 和 [profile-date-registered] 提取其他用户信息。

影响范围

ProfilePress

ProfilePress 插件所有版本至 4.17.4(含)。

漏洞详情

漏洞类型为敏感信息暴露,成因是 get_user_profile_structure 在处理 Member Directory 逐行用户重绑定时未正确校验用户身份与短代码上下文。攻击者可在 [pp-custom-html] 短代码中注入 base64 编码的载荷,触发 [profile-email]、[profile-username]、[profile-date-registered] 等短代码,从而读取任意用户的邮箱、登录名和注册日期。当 WordPress 的 users_can_register 选项开启时,未认证攻击者还可通过插件注册处理器传入 reg_nickname 和 reg_bio 字段,利用拆分短代码片段绕过 nonce 校验实施攻击。

利用条件与风险

认证攻击者需具备订阅者及以上权限即可利用;若站点开放用户注册,未认证攻击者也可利用,实战中可批量收集用户敏感信息用于后续钓鱼或撞库。

修复建议

建议升级 ProfilePress 至 4.17.4 之后的修复版本;临时缓解措施包括关闭 users_can_register 注册选项、限制 Member Directory 与自定义短代码的使用,或对相关短代码输出进行权限校验。具体修复版本请以官方公告为准。

原始情报

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract other users’ email addresses, login names, and registration dates via the Member Directory’s per-row user rebinding when attacker-controlled base64 payloads in the [pp-custom-html] shortcode invoke [profile-email], [profile-username], and [profile-date-registered]. When the WordPress users_can_register option is enabled, unauthenticated attackers can also exploit this vulnerability by supplying the split shortcode fragments through the plugin’s own registration handler, which processes the reg_nickname and reg_bio fields without a nonce requirement.