Profilepress

Properfraction · 34 CVEs

CVE-2026-66047
CRITICAL

ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE

Aug 31, 2026

CVE-2026-41556
MEDIUM

WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability

Jun 15, 2026

CVE-2024-13121
LOW

Paid Membership Plugin < 4.15.20 - Admin+ Stored XSS

Feb 13, 2025

CVE-2024-13120
MEDIUM

ProfilePress < 4.15.20 - Admin+ Stored XSS

Feb 13, 2025

CVE-2024-13119
MEDIUM

ProfilePress < 4.15.20 - Admin+ Stored XSS

Feb 13, 2025

CVE-2024-10518
MEDIUM

ProfilePress < 4.15.15 - Admin+ Stored XSS

Dec 12, 2024

CVE-2024-10517
MEDIUM

ProfilePress < 4.15.15 - Admin+ Stored XSS

Dec 12, 2024

CVE-2023-41953
MEDIUM

WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability

Dec 9, 2024

CVE-2023-50882
MEDIUM

WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability

Dec 9, 2024

CVE-2024-11083
MEDIUM

ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

Nov 27, 2024

CVE-2024-9947
CRITICAL

ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider

Oct 23, 2024

CVE-2024-2861
MEDIUM

ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget

May 23, 2024

CVE-2023-41954
HIGH

WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability

May 17, 2024

CVE-2024-2867
MEDIUM

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <…

May 2, 2024

CVE-2024-3210
MEDIUM

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <…

Apr 10, 2024

CVE-2024-1806
MEDIUM

ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortco…

Mar 13, 2024

CVE-2024-1409
MEDIUM

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <…

Mar 13, 2024

CVE-2024-1535
MEDIUM

ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Mar 13, 2024

CVE-2024-1408
MEDIUM

ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode

Feb 20, 2024

CVE-2024-1519
MEDIUM

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <…

Feb 20, 2024

CVE-2024-1570
MEDIUM

ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Feb 20, 2024

CVE-2024-1046
MEDIUM

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <…

Feb 5, 2024

CVE-2022-45083
HIGH

WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection

Jan 19, 2024

CVE-2023-44150
HIGH

WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure

Nov 30, 2023

CVE-2023-23830
HIGH

WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)

May 3, 2023

Showing 1 to 25 of 34 CVEs