LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3453 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: March 11, 2026

ProfilePress WordPress Plugin - Broken Access Control

Published: March 11, 2026Updated: March 11, 2026Remote Exploitable

Overview

ProfilePress WordPress plugin <= 4.16.11 contains an insecure direct object reference caused by missing ownership validation on change_plan_sub_id in process_checkout(), letting authenticated subscribers cancel others' subscriptions.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 4.1%(Probability of exploitation in next 30 days)

Impact

Authenticated attackers can cancel other users' active subscriptions, causing immediate loss of paid access.

Mitigation

Update to the latest version beyond 4.16.11.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 11, 2026

🟠 CVE-2026-3453 - High (8.1) The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to missing ownership validation on the change_plan_sub_id parameter in the process_checkout() functi... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-3453/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-3453
Severity
High
CVSS Score
8.1
Type
broken_access_control
Status
unconfirmed
EPSS
4.1%
Social Posts
1

CWE

  • CWE-639

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS Score

4.1%Probability of exploitation in the next 30 days