plugin

Wp Register Profile With Shortcode Vulnerabilities

8 known security issues reported for the Wp Register Profile With Shortcode WordPress plugin. Most recent disclosed Jul 10, 2025.

1 high 3 medium

Running Wp Register Profile With Shortcode on your site? Check whether your installed version is affected.

Scan your site free

WP Register Profile With Shortcode <= 3.6.2 - Authenticated (Contributor+) Sensitive Information Exposure

medium

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'rp_user_data' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data from user meta...

CVSS:
6.5
Affected:
up to 3.6.2
Fixed in:
3.6.3
Disclosed:
Jul 10, 2025

CVE-2025-4593 on NVD →

WP Register Profile With Shortcode [wp-register-profile-with-shortcode] <= 3.6.2 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com WP Register Profile With Shortcode allows Stored XSS. This issue affects WP Register Profile With Shortcode: from n/a through 3.6.1.

Affected:
up to 3.6.2
Fix:
No patched version reported
Disclosed:
Jun 20, 2025

CVE-2025-50042 on NVD →

WP Register Profile With Shortcode <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...

CVSS:
6.4
Affected:
up to 3.6.2
Fix:
No patched version reported
Disclosed:
Jun 19, 2025

CVE-2025-50042 on NVD →

WP Register Profile With Shortcode [wp-register-profile-with-shortcode] < 3.6.0

unknown

[en] The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This is due to missing or incorrect nonce validation on the update_password_validate function. This makes it possible for unauthenticated attackers to reset a user's pass...

Affected:
up to 3.6.0
Fixed in:
3.6.0
Disclosed:
Jan 11, 2024

CVE-2023-5448 on NVD →

WP Register Profile With Shortcode <= 3.5.9 - Cross-Site Request Forgery to User Password Reset

high

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This is due to missing or incorrect nonce validation on the update_password_validate function. This makes it possible for unauthenticated attackers to reset a user's password...

CVSS:
8.8
Affected:
up to 3.5.9
Fixed in:
3.6.0
Disclosed:
Jan 10, 2024

CVE-2023-5448 on NVD →

WP Register Profile With Shortcode [wp-register-profile-with-shortcode] < 3.5.8

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Aviplugins.Com WP Register Profile With Shortcode plugin <= 3.5.7 versions.

Affected:
up to 3.5.8
Fixed in:
3.5.8
Disclosed:
Jun 12, 2023

CVE-2023-23818 on NVD →

WP Register Profile With Shortcode <= 3.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, and including, 3.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inje...

CVSS:
4.4
Affected:
up to 3.5.7
Fixed in:
3.5.8
Disclosed:
May 12, 2023

CVE-2023-23818 on NVD →

WP Register Profile With Shortcode [wp-register-profile-with-shortcode] < 3.6.3

unknown
Affected:
up to 3.6.3
Fixed in:
3.6.3

CVE-2025-4593 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database