Skip to main content

Vendor/product archive

properfraction / profilepress CVEs

Beta · best-effort

34 CVEs tagged to properfraction / profilepress4 Critical, 5 High, 24 Medium, 1 Low, 0 Unrated.

CVE-2024-13121

Published Feb 13, 2025

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of it…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-13120

Published Feb 13, 2025

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of it…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13119

Published Feb 13, 2025

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of it…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10518

Published Dec 12, 2024

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of it…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10517

Published Dec 12, 2024

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of it…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41953

Published Dec 9, 2024

Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-50882

Published Dec 9, 2024

Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Profil…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11083

Published Nov 27, 2024

The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress core search feature. This mak…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9947

Published Oct 23, 2024

The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2861

Published May 23, 2024

The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ProfilePress User Panel widget in all versions up to, and including, 4.15.8 due to insuf…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41954

Published May 17, 2024

Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2867

Published May 2, 2024

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site S…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3210

Published Apr 10, 2024

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site S…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1806

Published Mar 13, 2024

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site S…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1535

Published Mar 13, 2024

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site S…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1409

Published Mar 13, 2024

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site S…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1570

Published Feb 29, 2024

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site S…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1519

Published Feb 29, 2024

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site S…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1408

Published Feb 29, 2024

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site S…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1046

Published Feb 5, 2024

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site S…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-45083

Published Jan 19, 2024

Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Cont…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44150

Published Nov 30, 2023

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Pro…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-23830

Published May 3, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-23820

Published May 3, 2023

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-23996

Published Apr 6, 2023

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.3 versions.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 34 CVEsPage 1 of 2