CVE-2026-66047 carries a CVSS 3.1 base score of 8.1 against ProfilePress (formerly distributed under the plugin slug wp-user-avatar), a WordPress user-profile plugin. NVD classifies it under both CWE-306 (Missing Authentication for Critical Function) and CWE-330 (Use of Insufficiently Random Values), and states the flaw is fixed in version 4.17.2. VulnCheck’s KEV feed reports the CVE as exploited, dated September 16, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-66047 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description states the plugin’s ppress_connect_process AJAX handler authenticates requests using a 32-bit connect token that an unauthenticated attacker can brute-force due to its limited value space. Once an attacker supplies a valid token, NVD states a caller-controlled URL passed through the handler’s file request parameter triggers silent installation and activation of an arbitrary plugin, resulting in PHP code execution as the web-server user. The CVSS vector marks this AC:H (high attack complexity), consistent with the brute-force step NVD’s description requires before the installation step can proceed.
We are reporting the weakness class and its impact as NVD describes them, not the specific brute-force approach or request sequence.
Evidence and confidence
- Medium confidence — the CVSS 8.1 score, the vector (
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-306/CWE-330 classification, the fixed version (4.17.2), and the described mechanism all trace to NVD alone in our current ingestion, corroborated by VulnCheck’s own published advisory on the same flaw. The exploitation report traces to VulnCheck KEV alone. - Below-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.00539, a 44.1st percentile score as of our ingestion — moderate for a flaw whose attack complexity NVD itself rates as high.
No field is in conflict between our two sources.
Why this matters
This CVE combines two distinct weaknesses that compound each other: a weak, brute-forceable 32-bit token (CWE-330) sitting in front of a completely unauthenticated action (CWE-306) that itself allows arbitrary plugin installation — one of the highest-impact actions a WordPress site permits, since an installed and activated plugin can execute arbitrary PHP as the web-server user. The high attack-complexity rating reflects the brute-force requirement, not a lack of severity once that step succeeds; any internet-facing WordPress site running a pre-4.17.2 version of this plugin should treat the token-based gate as a speed bump rather than a real barrier.
Frequently Asked Questions
What is CVE-2026-66047? A CVSS 8.1 vulnerability (CWE-306/CWE-330) in the ProfilePress WordPress plugin before version 4.17.2, allowing unauthenticated attackers who brute-force a weak 32-bit connect token to trigger silent installation and activation of an arbitrary plugin, achieving PHP code execution.
Is CVE-2026-66047 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 16, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this? No. NVD’s description states the attack is fully unauthenticated, though it requires brute-forcing a 32-bit token first — reflected in the CVSS vector’s high attack-complexity rating.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Version 4.17.2, per NVD and the plugin vendor’s own changelog.
Severity, vector, weakness classification, and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-66047, corroborated by VulnCheck’s own advisory. Exploitation status and the September 16, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.