Profilepress
Properfraction · 34 CVEs
ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE
Aug 31, 2026
WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability
Jun 15, 2026
Paid Membership Plugin < 4.15.20 - Admin+ Stored XSS
Feb 13, 2025
ProfilePress < 4.15.20 - Admin+ Stored XSS
Feb 13, 2025
ProfilePress < 4.15.20 - Admin+ Stored XSS
Feb 13, 2025
ProfilePress < 4.15.15 - Admin+ Stored XSS
Dec 12, 2024
ProfilePress < 4.15.15 - Admin+ Stored XSS
Dec 12, 2024
WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability
Dec 9, 2024
WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability
Dec 9, 2024
ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
Nov 27, 2024
ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider
Oct 23, 2024
ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget
May 23, 2024
WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability
May 17, 2024
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <…
May 2, 2024
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <…
Apr 10, 2024
ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortco…
Mar 13, 2024
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <…
Mar 13, 2024
ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Mar 13, 2024
ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode
Feb 20, 2024
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <…
Feb 20, 2024
ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Feb 20, 2024
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <…
Feb 5, 2024
WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection
Jan 19, 2024
WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure
Nov 30, 2023
WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)
May 3, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-66047 | ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE | CRITICAL | 0.92% | Aug 31, 2026 |
| CVE-2026-41556 | WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 0.22% | Jun 15, 2026 |
| CVE-2024-13121 | Paid Membership Plugin < 4.15.20 - Admin+ Stored XSS | LOW | 0.32% | Feb 13, 2025 |
| CVE-2024-13120 | ProfilePress < 4.15.20 - Admin+ Stored XSS | MEDIUM | 0.31% | Feb 13, 2025 |
| CVE-2024-13119 | ProfilePress < 4.15.20 - Admin+ Stored XSS | MEDIUM | 0.36% | Feb 13, 2025 |
| CVE-2024-10518 | ProfilePress < 4.15.15 - Admin+ Stored XSS | MEDIUM | 0.35% | Dec 12, 2024 |
| CVE-2024-10517 | ProfilePress < 4.15.15 - Admin+ Stored XSS | MEDIUM | 0.35% | Dec 12, 2024 |
| CVE-2023-41953 | WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability | MEDIUM | 0.41% | Dec 9, 2024 |
| CVE-2023-50882 | WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability | MEDIUM | 0.50% | Dec 9, 2024 |
| CVE-2024-11083 | ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure | MEDIUM | 0.41% | Nov 27, 2024 |
| CVE-2024-9947 | ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider | CRITICAL | 0.53% | Oct 23, 2024 |
| CVE-2024-2861 | ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget | MEDIUM | 0.29% | May 23, 2024 |
| CVE-2023-41954 | WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability | HIGH | 1.30% | May 17, 2024 |
| CVE-2024-2867 | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+)… | MEDIUM | 0.38% | May 2, 2024 |
| CVE-2024-3210 | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+)… | MEDIUM | 0.43% | Apr 10, 2024 |
| CVE-2024-1806 | ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode | MEDIUM | 0.56% | Mar 13, 2024 |
| CVE-2024-1409 | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+)… | MEDIUM | 0.44% | Mar 13, 2024 |
| CVE-2024-1535 | ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | MEDIUM | 0.57% | Mar 13, 2024 |
| CVE-2024-1408 | ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode | MEDIUM | 0.60% | Feb 20, 2024 |
| CVE-2024-1519 | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-… | MEDIUM | 0.57% | Feb 20, 2024 |
| CVE-2024-1570 | ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | MEDIUM | 0.48% | Feb 20, 2024 |
| CVE-2024-1046 | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+)… | MEDIUM | 0.37% | Feb 5, 2024 |
| CVE-2022-45083 | WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection | HIGH | 0.58% | Jan 19, 2024 |
| CVE-2023-44150 | WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure | HIGH | 0.66% | Nov 30, 2023 |
| CVE-2023-23830 | WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS) | HIGH | 0.41% | May 3, 2023 |
Showing 1 to 25 of 34 CVEs