Product
properfraction profilepress
39 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-13121
CVE-2024-13120
CVE-2024-13119
CVE-2024-10518
CVE-2024-10517
CVE-2023-41953
CVE-2023-50882
CVE-2024-11083
CVE-2024-9947
CVE-2024-2861
CVE-2023-41954
CVE-2024-2867
CVE-2024-3210
CVE-2024-1806
CVE-2024-1535
CVE-2024-1409
CVE-2024-1570
CVE-2024-1519
CVE-2024-1408
CVE-2024-1046
CVE-2022-45083
CVE-2023-44150
CVE-2023-23830
CVE-2023-23820
CVE-2023-23996
CVE-2022-47444
CVE-2022-4698
CVE-2022-4697
CVE-2021-24955
CVE-2021-24954
CVE-2021-24939
CVE-2021-24522
CVE-2021-24450
CVE-2021-34624
CVE-2021-34623
CVE-2021-34622
CVE-2021-34621
CVE-2016-10925
CVE-2019-15115
< 4.15.20
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin befor
< 4.15.20
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin befor
< 4.15.20
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin befor
< 4.15.15
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin befor
< 4.15.5
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin befor
< 4.13.2
Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through
< 4.13.3
Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access
< 4.15.19
The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.1
< 4.11.2
The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. Thi
< 4.15.9
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ProfilePress User Panel widget in all v
< 4.13.2
Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue af
< 4.15.5
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress plugin f
< 4.15.6
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress plugin f
< 4.15.2
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress plugin f
< 4.15.3
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress plugin f
< 4.15.1
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress plugin f
< 4.15.0
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress plugin f
< 4.15.0
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress plugin f
< 4.15.0
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress plugin f
<= 4.14.3
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress plugin f
< 4.4.0
Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registrati
< 4.13.3
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ProfilePress Membership Team Paid Membership Plugin, E
< 4.5.5
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
< 4.5.5
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4
< 4.5.4
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.3 versi
<= 4.5.3
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Regi
< 4.5.1
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions up to, and
< 4.5.1
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_url’ p
< 3.2.3
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of t
< 3.2.3
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress
< 3.0.0.5
The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login_url and r
< 3.1.11
The User Registration, User Profile, Login & Membership - ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's
< 3.1.8
The User Registration, User Profiles, Login & Membership - ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 di
>= 3.0.0 and <= 3.1.3
A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plug
>= 3.0.0 and <= 3.1.3
A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress pl
>= 3.0.0 and <= 3.1.3
A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordP
>= 3.0.0 and <= 3.1.3
A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPr
< 2.9.1
The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs.
< 2.9.2
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.