CVE-2025-13642 | ProfilePress Plugin up to 4.16.7 on WordPress Shortcode Type code injection
A vulnerability described as critical has been identified in ProfilePress Plugin up to 4.16.7 on WordPress. This issue affects some unknown processing of the component Shortcode Handler. The manipulation of the argument Type results in code injection.
This vulnerability is known as CVE-2025-13642. It is possible to launch the attack remotely. No exploit is available.