CVE-2026-12497: ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some valid ways of configuring the offered roles the handler ignores the restriction and falls back to accepting any non-administrator role. Combined with the absence of a nonce on the public registration handler, this allows an unauthenticated visitor to register an account with a higher role, such as Editor or Author, than the form was configured to offer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress ProfilePressto a version that resolves this vulnerability.Fixed in 4.16.18 - Upgrade
Upgrade
WordPress Paid Membership Pluginto a version that resolves this vulnerability.Fixed in 4.16.18 - Upgrade
Upgrade
WordPress Ecommerceto a version that resolves this vulnerability.Fixed in 4.16.18 - Upgrade
Upgrade
WordPress User Registration Formto a version that resolves this vulnerability.Fixed in 4.16.18 - Upgrade
Upgrade
WordPress Login Formto a version that resolves this vulnerability.Fixed in 4.16.18 - Upgrade
Upgrade
WordPress User Profileto a version that resolves this vulnerability.Fixed in 4.16.18 - Upgrade
Upgrade
WordPress Restrict Contentto a version that resolves this vulnerability.Fixed in 4.16.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12497?
CVE-2026-12497 has a risk rating of 71, indicating a significant security concern.
How do I fix CVE-2026-12497?
To remediate CVE-2026-12497, update the ProfilePress plugin to version 4.16.18 or later.
What are the main vulnerabilities associated with CVE-2026-12497?
CVE-2026-12497 allows unauthenticated privilege escalation via improper role selection during user registration.
Who is affected by CVE-2026-12497?
CVE-2026-12497 affects users of the ProfilePress plugin on WordPress versions prior to 4.16.18.
Is CVE-2026-12497 specific to any WordPress version?
Yes, CVE-2026-12497 specifically affects the ProfilePress plugin used in WordPress implementations before version 4.16.18.