Skip to main content

Vendor archive

properfraction CVEs

Beta · best-effort

35 CVEs tagged to vendor properfraction4 Critical, 5 High, 25 Medium, 1 Low, 0 Unrated.

CVE-2023-23996

Published Apr 6, 2023

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.3 versions.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47444

Published Mar 29, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restric…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-4698

Published Dec 23, 2022

The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions up to, and including, 4.5.0 due to insufficient input saniti…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4697

Published Dec 23, 2022

The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_url’ parameter in versions up to, and including, 4.5.0 due…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24522

Published Aug 9, 2021

The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24450

Published Aug 2, 2021

The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 did not sanitise or escape some of its settings bef…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34624

Published Jul 7, 2021

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-34623

Published Jul 7, 2021

A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitra…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-34622

Published Jul 7, 2021

A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalat…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-34621

Published Jul 7, 2021

A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 26-35 of 35 CVEsPage 2 of 2