CVE-2026-13352: CWE-434 Unrestricted Upload of File with Dangerous Type in properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the global WordPress MIME allowlist, without scoping the expansion to digital-product upload contexts. This makes it possible for authenticated attackers, with author-level access and above, to upload files that may be executable, which makes remote code execution possible. This filter is registered globally on every request regardless of whether the digital products feature is configured or in use, meaning the expanded MIME allowlist affects all WordPress upload contexts site-wide.
AI Analysis
Technical Summary
CVE-2026-13352 is a vulnerability in the ProfilePress WordPress plugin that allows arbitrary file upload due to improper scoping of MIME type expansion. The plugin unconditionally registers an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the global MIME allowlist, without restricting this to digital product uploads. As a result, authenticated users with author-level permissions can upload executable files anywhere on the site, potentially leading to remote code execution. This filter is applied globally on every request, affecting all WordPress upload contexts regardless of whether the digital products feature is enabled.
Potential Impact
An attacker with author-level or higher privileges can upload executable files to the WordPress site, which may lead to remote code execution. This compromises the confidentiality, integrity, and availability of the affected site. The vulnerability affects all upload contexts site-wide due to the global registration of the MIME type filter.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict author-level user permissions and avoid granting upload capabilities to untrusted users. Monitor for updates from the plugin vendor and apply patches promptly once released.
CVE-2026-13352: CWE-434 Unrestricted Upload of File with Dangerous Type in properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Description
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the global WordPress MIME allowlist, without scoping the expansion to digital-product upload contexts. This makes it possible for authenticated attackers, with author-level access and above, to upload files that may be executable, which makes remote code execution possible. This filter is registered globally on every request regardless of whether the digital products feature is configured or in use, meaning the expanded MIME allowlist affects all WordPress upload contexts site-wide.
CVSS v3.1
Score 8.8high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-13352 is a vulnerability in the ProfilePress WordPress plugin that allows arbitrary file upload due to improper scoping of MIME type expansion. The plugin unconditionally registers an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the global MIME allowlist, without restricting this to digital product uploads. As a result, authenticated users with author-level permissions can upload executable files anywhere on the site, potentially leading to remote code execution. This filter is applied globally on every request, affecting all WordPress upload contexts regardless of whether the digital products feature is enabled.
Potential Impact
An attacker with author-level or higher privileges can upload executable files to the WordPress site, which may lead to remote code execution. This compromises the confidentiality, integrity, and availability of the affected site. The vulnerability affects all upload contexts site-wide due to the global registration of the MIME type filter.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict author-level user permissions and avoid granting upload capabilities to untrusted users. Monitor for updates from the plugin vendor and apply patches promptly once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-06-25T16:24:12.456Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a59b40868715ace4359f511
Added to database: 07/17/2026, 04:48:08 UTC
Last enriched: 07/17/2026, 05:02:36 UTC
Last updated: 08/31/2026, 10:52:07 UTC
Views: 100
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.