WP Register Profile With Shortcode <= 3.6.2 - Authenticated (Contributor+) Sensitive Information Exposure
medium
The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'rp_user_data' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data from user meta...
- CVSS:
- 6.5
- Affected:
- up to 3.6.2
- Fixed in:
- 3.6.3
- Disclosed:
- Jul 10, 2025
CVE-2025-4593 on NVD →
WP Register Profile With Shortcode [wp-register-profile-with-shortcode] <= 3.6.2 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com WP Register Profile With Shortcode allows Stored XSS. This issue affects WP Register Profile With Shortcode: from n/a through 3.6.1.
- Affected:
- up to 3.6.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2025
CVE-2025-50042 on NVD →
WP Register Profile With Shortcode <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...
- CVSS:
- 6.4
- Affected:
- up to 3.6.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 19, 2025
CVE-2025-50042 on NVD →
WP Register Profile With Shortcode [wp-register-profile-with-shortcode] < 3.6.0
unknown
[en] The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This is due to missing or incorrect nonce validation on the update_password_validate function. This makes it possible for unauthenticated attackers to reset a user's pass...
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
- Disclosed:
- Jan 11, 2024
CVE-2023-5448 on NVD →
WP Register Profile With Shortcode <= 3.5.9 - Cross-Site Request Forgery to User Password Reset
high
The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This is due to missing or incorrect nonce validation on the update_password_validate function. This makes it possible for unauthenticated attackers to reset a user's password...
- CVSS:
- 8.8
- Affected:
- up to 3.5.9
- Fixed in:
- 3.6.0
- Disclosed:
- Jan 10, 2024
CVE-2023-5448 on NVD →
WP Register Profile With Shortcode [wp-register-profile-with-shortcode] < 3.5.8
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Aviplugins.Com WP Register Profile With Shortcode plugin <= 3.5.7 versions.
- Affected:
- up to 3.5.8
- Fixed in:
- 3.5.8
- Disclosed:
- Jun 12, 2023
CVE-2023-23818 on NVD →
WP Register Profile With Shortcode <= 3.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, and including, 3.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inje...
- CVSS:
- 4.4
- Affected:
- up to 3.5.7
- Fixed in:
- 3.5.8
- Disclosed:
- May 12, 2023
CVE-2023-23818 on NVD →
WP Register Profile With Shortcode [wp-register-profile-with-shortcode] < 3.6.3
unknown
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.3
CVE-2025-4593 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database