📦 Profilepress

by Properfraction

🔍 What is Profilepress?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-34621

CRITICAL CVSS 9.8 Jul 7, 2021

This critical vulnerability in the ProfilePress WordPress plugin allows unauthenticated attackers to register new user accounts with administrator privileges. It affects WordPress sites running Profil...

CVE-2021-34623

CRITICAL CVSS 9.8 Jul 7, 2021

This critical vulnerability in the ProfilePress WordPress plugin allows unauthenticated attackers to upload arbitrary files during user registration or profile updates. This can lead to remote code ex...

CVE-2024-9947

HIGH CVSS 8.1 Oct 23, 2024

The ProfilePress Pro WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user, including administrators, if they know the user's...

CVE-2023-44150

HIGH CVSS 7.5 Nov 30, 2023

This vulnerability in the ProfilePress WordPress plugin exposes sensitive information via debug logs to unauthorized actors. It affects all WordPress sites using ProfilePress versions up to 4.13.2, po...

CVE-2023-23830

HIGH CVSS 7.1 May 3, 2023

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using ProfilePress plugin versions 4.5.4 and earlier. When exploited, it enables cross-site scripti...

CVE-2022-47444

HIGH CVSS 7.1 Mar 29, 2023

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using the ProfilePress plugin. When victims view pages containing the injected scripts, attackers c...

CVE-2024-13120

MEDIUM CVSS 4.8 Feb 13, 2025

This vulnerability allows high-privilege WordPress users (like administrators) to inject malicious scripts into plugin settings, which then execute when other users view those settings. It affects Wor...

CVE-2024-10517

MEDIUM CVSS 4.8 Dec 12, 2024

This vulnerability allows high-privilege WordPress users (like administrators) to inject malicious scripts into Drag & Drop Builder fields, which then execute when other users view those pages. It aff...

CVE-2023-41953

MEDIUM CVSS 5.3 Dec 9, 2024

This CVE describes a missing authorization vulnerability in the ProfilePress WordPress plugin that allows unauthorized users to access restricted functionality. It affects all ProfilePress installatio...

CVE-2024-11083

MEDIUM CVSS 5.3 Nov 27, 2024

The ProfilePress WordPress plugin exposes sensitive information through WordPress core search functionality. Unauthenticated attackers can access restricted content intended for administrators and oth...

CVE-2024-2867

MEDIUM CVSS 6.4 May 2, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts via the 'title' parameter in the ProfilePress plugin. The scripts are stored...