plugin

Wp User Avatar Vulnerabilities

91 known security issues reported for the Wp User Avatar WordPress plugin. Most recent disclosed Aug 15, 2026.

5 critical 8 high 35 medium

Running Wp User Avatar on your site? Check whether your installed version is affected.

Scan your site free

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.19 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field

medium

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.19. This is due to the software allowing users to execute an action that does not p...

CVSS:
5.4
Affected:
up to 4.16.19
Fixed in:
4.17.0
Disclosed:
Aug 15, 2026

CVE-2026-18385 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion

high

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upl...

CVSS:
8.8
Affected:
up to 4.16.18
Fixed in:
4.16.19
Disclosed:
Jul 16, 2026

CVE-2026-13352 on NVD →

ProfilePress <= 4.16.17 - Unauthenticated Privilege Escalation

critical

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.16.17. This makes it possible for unauthenticated attackers to register as higher privileged roles...

CVSS:
9.8
Affected:
up to 4.16.17
Fixed in:
4.16.18
Disclosed:
Jul 3, 2026

CVE-2026-12497 on NVD →

ProfilePress <= 4.16.16 - Insecure Direct Object Reference to Authenticated (Subscriber+) Subscription Cancellation

medium

The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.16.16. This is due to missing ownership verification on the sub_id parameter before performing subscription actions. This makes it possible for authenticated attackers, with subscriber-level acces...

CVSS:
4.3
Affected:
up to 4.16.16
Fixed in:
4.16.17
Disclosed:
Jun 6, 2026

CVE-2026-10820 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.16.13 due to insufficient input sanitization and output escaping. This makes it possible for aut...

CVSS:
6.4
Affected:
up to 4.16.13
Fixed in:
4.16.14
Disclosed:
Apr 23, 2026

CVE-2026-41556 on NVD →

ProfilePress <= 4.16.12 - Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan Subscription

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.16.12. This is due to the 'process_checkout' function not properly enforcing the plan active statu...

CVSS:
4.3
Affected:
up to 4.16.12
Fixed in:
4.16.13
Disclosed:
Apr 15, 2026

CVE-2026-4949 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing Fields

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.11. This is due to the plugin allowing user-supplied billing field values from the chec...

CVSS:
6.5
Affected:
up to 4.16.11
Fixed in:
4.16.12
Disclosed:
Apr 3, 2026

CVE-2026-3309 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass

high

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on the `change_plan_sub_id...

CVSS:
7.1
Affected:
up to 4.16.11
Fixed in:
4.16.12
Disclosed:
Apr 3, 2026

CVE-2026-3445 on NVD →

ProfilePress - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration vulnerability

high

Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration vulnerability

CVSS:
8.1
Affected:
up to 4.16.11
Fixed in:
4.16.12
Disclosed:
Mar 11, 2026

ProfilePress <= 4.16.11 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration

high

The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to missing ownership validation on the change_plan_sub_id parameter in the process_checkout() function. The ppress_process_checkout AJAX handler accepts a user-controlled su...

CVSS:
8.1
Affected:
up to 4.16.11
Fixed in:
4.16.12
Disclosed:
Mar 10, 2026

CVE-2026-3453 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.16.8

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.7 due to insufficient input sanitization on the `type` parameter in the form previ...

Affected:
up to 4.16.8
Fixed in:
4.16.8
Disclosed:
Dec 9, 2025

CVE-2025-13642 on NVD →

ProfilePress <= 4.16.7 - Authenticated (Subscriber+) Arbitrary Shortcode Execution

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.7 due to insufficient input sanitization on the `type` parameter in the form preview fu...

CVSS:
5.4
Affected:
up to 4.16.7
Fixed in:
4.16.8
Disclosed:
Dec 8, 2025

CVE-2025-13642 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.4 - Unauthenticated Arbitrary Shortcode Execution

medium

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.4. This is due to the software allowing users to execute an action that does not pr...

CVSS:
6.5
Affected:
up to 4.16.4
Fixed in:
4.16.5
Disclosed:
Aug 15, 2025

CVE-2025-8878 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.20

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered...

Affected:
up to 4.15.20
Fixed in:
4.15.20
Disclosed:
Feb 13, 2025

CVE-2024-13121 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.20

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered...

Affected:
up to 4.15.20
Fixed in:
4.15.20
Disclosed:
Feb 13, 2025

CVE-2024-13120 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.20

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered...

Affected:
up to 4.15.20
Fixed in:
4.15.20
Disclosed:
Feb 13, 2025

CVE-2024-13119 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.19 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.19 due to insufficient input sanitization and output escaping. This ma...

CVSS:
4.4
Affected:
up to 4.15.19
Fixed in:
4.15.20
Disclosed:
Jan 23, 2025

CVE-2024-13119 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.19 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.19 due to insufficient input sanitization and output escaping. This ma...

CVSS:
4.4
Affected:
up to 4.15.19
Fixed in:
4.15.20
Disclosed:
Jan 23, 2025

CVE-2024-13121 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.19 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.19 due to insufficient input sanitization and output escaping. This ma...

CVSS:
4.4
Affected:
up to 4.15.19
Fixed in:
4.15.20
Disclosed:
Jan 23, 2025

CVE-2024-13120 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.15

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Drag & Drop Builder fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even w...

Affected:
up to 4.15.15
Fixed in:
4.15.15
Disclosed:
Dec 12, 2024

CVE-2024-10517 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.15

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Membership Plan settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even whe...

Affected:
up to 4.15.15
Fixed in:
4.15.15
Disclosed:
Dec 12, 2024

CVE-2024-10518 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.13.3

unknown

[en] Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.13.2.

Affected:
up to 4.13.3
Fixed in:
4.13.3
Disclosed:
Dec 9, 2024

CVE-2023-50882 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.13.2

unknown

[en] Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1.

Affected:
up to 4.13.2
Fixed in:
4.13.2
Disclosed:
Dec 9, 2024

CVE-2023-41953 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.19

unknown

[en] The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such a...

Affected:
up to 4.15.19
Fixed in:
4.15.19
Disclosed:
Nov 27, 2024

CVE-2024-11083 on NVD →

ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

medium

The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as adm...

CVSS:
5.3
Affected:
up to 4.15.18
Fixed in:
4.15.19
Disclosed:
Nov 26, 2024

CVE-2024-11083 on NVD →

ProfilePress <= 4.15.14 - Authenticated (Admin+) Stored Cross-Site Scripting via "Labels"

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via "Label" settings in all versions up to, and including, 4.15.14 due to insufficient input sanitization and output escaping. This...

CVSS:
4.4
Affected:
up to 4.15.14
Fixed in:
4.15.15
Disclosed:
Nov 21, 2024

CVE-2024-10517 on NVD →

ProfilePress <= 4.15.14 - Authenticated (Admin+) Stored Cross-Site Scripting via "Product Files"

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via "Product Files" settings in all versions up to, and including, 4.15.14 due to insufficient input sanitization and output escapin...

CVSS:
4.4
Affected:
up to 4.15.14
Fixed in:
4.15.15
Disclosed:
Nov 21, 2024

CVE-2024-10518 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.9

unknown

[en] The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ProfilePress User Panel widget in all versions up to, and including, 4.15.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with con...

Affected:
up to 4.15.9
Fixed in:
4.15.9
Disclosed:
May 23, 2024

CVE-2024-2861 on NVD →

ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget

medium

The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ProfilePress User Panel widget in all versions up to, and including, 4.15.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...

CVSS:
6.4
Affected:
up to 4.15.8
Fixed in:
4.15.9
Disclosed:
May 22, 2024

CVE-2024-2861 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.13.2

unknown

[en] Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.

Affected:
up to 4.13.2
Fixed in:
4.13.2
Disclosed:
May 17, 2024

CVE-2023-41954 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.5

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 4.15.4 due to insufficient input sanitization and output escapi...

Affected:
up to 4.15.5
Fixed in:
4.15.5
Disclosed:
May 2, 2024

CVE-2024-2867 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 4.15.4 due to insufficient input sanitization and output escaping. T...

CVSS:
6.4
Affected:
up to 4.15.4
Fixed in:
4.15.5
Disclosed:
Apr 11, 2024

CVE-2024-2867 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.6

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'reg-single-checkbox' shortcode in all versions up to, and including, 4.15.5 due to insufficient input sanitiz...

Affected:
up to 4.15.6
Fixed in:
4.15.6
Disclosed:
Apr 10, 2024

CVE-2024-3210 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'reg-single-checkbox'

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'reg-single-checkbox' shortcode in all versions up to, and including, 4.15.5 due to insufficient input sanitization...

CVSS:
6.4
Affected:
up to 4.15.5
Fixed in:
4.15.6
Disclosed:
Apr 9, 2024

CVE-2024-3210 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.3

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.15.2 due to insufficient input sanitization and output es...

Affected:
up to 4.15.3
Fixed in:
4.15.3
Disclosed:
Mar 13, 2024

CVE-2024-1535 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.1

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.15.1 due to insufficient input sanitization and output es...

Affected:
up to 4.15.1
Fixed in:
4.15.1
Disclosed:
Mar 13, 2024

CVE-2024-1806 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.1

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [reg-select-role] shortcode in all versions up to, and including, 4.15.0 due to insufficient input sanitizatio...

Affected:
up to 4.15.1
Fixed in:
4.15.1
Disclosed:
Mar 13, 2024

CVE-2024-1409 on NVD →

ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.15.2 due to insufficient input sanitization and output escapin...

CVSS:
6.4
Affected:
up to 4.15.2
Fixed in:
4.15.3
Disclosed:
Mar 12, 2024

CVE-2024-1535 on NVD →

ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.15.1 due to insufficient input sanitization and output escapin...

CVSS:
6.4
Affected:
up to 4.15.1
Fixed in:
4.15.2
Disclosed:
Feb 23, 2024

CVE-2024-1806 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via [reg-select-role] Shortcode

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [reg-select-role] shortcode in all versions up to, and including, 4.15.0 due to insufficient input sanitization and...

CVSS:
6.4
Affected:
up to 4.15.0
Fixed in:
4.15.1
Disclosed:
Feb 22, 2024

CVE-2024-1409 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.0

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edit-profile-text-box shortcode in all versions up to, and including, 4.14.4 due to insufficient input sanitiz...

Affected:
up to 4.15.0
Fixed in:
4.15.0
Disclosed:
Feb 20, 2024

CVE-2024-1408 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.0

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 4.14.4 due to insufficient input sanitization and output escapin...

Affected:
up to 4.15.0
Fixed in:
4.15.0
Disclosed:
Feb 20, 2024

CVE-2024-1519 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.15.0

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's login-password shortcode in all versions up to, and including, 4.14.4 due to insufficient input sanitization a...

Affected:
up to 4.15.0
Fixed in:
4.15.0
Disclosed:
Feb 20, 2024

CVE-2024-1570 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-Site Scripting

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 4.14.4 due to insufficient input sanitization and output escaping. Th...

CVSS:
6.5
Affected:
up to 4.14.4
Fixed in:
4.15.0
Disclosed:
Feb 19, 2024

CVE-2024-1519 on NVD →

ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's login-password shortcode in all versions up to, and including, 4.14.4 due to insufficient input sanitization and ou...

CVSS:
6.4
Affected:
up to 4.14.4
Fixed in:
4.15.0
Disclosed:
Feb 19, 2024

CVE-2024-1570 on NVD →

ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edit-profile-text-box shortcode in all versions up to, and including, 4.14.4 due to insufficient input sanitization...

CVSS:
6.4
Affected:
up to 4.14.4
Fixed in:
4.15.0
Disclosed:
Feb 19, 2024

CVE-2024-1408 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.14.4

unknown

[en] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'reg-number-field' shortcode in all versions up to, and including, 4.14.3 due to insufficient input sanitization...

Affected:
up to 4.14.4
Fixed in:
4.14.4
Disclosed:
Feb 5, 2024

CVE-2024-1046 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'reg-number-field' shortcode in all versions up to, and including, 4.14.3 due to insufficient input sanitization and...

CVSS:
6.4
Affected:
up to 4.14.3
Fixed in:
4.14.4
Disclosed:
Feb 1, 2024

CVE-2024-1046 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.4.0

unknown

[en] Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Con...

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Jan 19, 2024

CVE-2022-45083 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.13.3

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile...

Affected:
up to 4.13.3
Fixed in:
4.13.3
Disclosed:
Nov 30, 2023

CVE-2023-44150 on NVD →

ProfilePress <= 4.13.2 - Information Disclosure via Debug Log

medium

The ProfilePress plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.13.2 via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may contain information like system errors which could contain sensitive inf...

CVSS:
5.3
Affected:
up to 4.13.2
Fixed in:
4.13.3
Disclosed:
Oct 2, 2023

CVE-2023-44150 on NVD →

ProfilePress <= 4.13.1 - Limited Privilege Escalation via 'acceptable_defined_roles'

high

The ProfilePress plugin for WordPress is vulnerable to limited privilege escalation in versions up to, and including, 4.13.1 via the 'acceptable_defined_roles' function due to incomplete validation on a user controlled key. This can allow unauthenticated attackers to elevate their privileges to a non-administrator role...

CVSS:
7.3
Affected:
up to 4.13.2
Fixed in:
4.13.2
Disclosed:
Sep 9, 2023

CVE-2023-41954 on NVD →

ProfilePress <= 4.13.1 Cross-Site Request Forgery via 'admin_notice'

medium

The ProfilePress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.13.1. This is due to missing or incorrect nonce validation on the 'admin_notice' function. This makes it possible for unauthenticated attackers to dismiss admin notices granted they can trick a site adm...

CVSS:
4.3
Affected:
up to 4.13.2
Fixed in:
4.13.2
Disclosed:
Sep 9, 2023

CVE-2023-41953 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.13.2

unknown

The ProfilePress plugin for WordPress is vulnerable to limited privilege escalation in versions up to, and including, 4.13.1 via the 'acceptable_defined_roles' function due to incomplete validation on a user controlled key. This can allow unauthenticated attackers to elevate their privileges to a non-administrator role...

Affected:
up to 4.13.2
Fixed in:
4.13.2
Disclosed:
Sep 9, 2023

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.13.2

unknown

The ProfilePress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.13.1. This is due to missing or incorrect nonce validation on the 'admin_notice' function. This makes it possible for unauthenticated attackers to dismiss admin notices granted they can trick a site adm...

Affected:
up to 4.13.2
Fixed in:
4.13.2
Disclosed:
Sep 9, 2023

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.11.0

unknown

Update the WordPress ProfilePress plugin to the latest available version (at least 4.11.0). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress ProfilePress Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML pa...

Affected:
up to 4.11.0
Fixed in:
4.11.0
Disclosed:
Jun 26, 2023

ProfilePress <= 4.10.3 - Reflected Cross-Site Scripting via error message

medium

The ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the error parameter in versions up to, and including, 4.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

CVSS:
6.1
Affected:
up to 4.11.0
Fixed in:
4.11.0
Disclosed:
Jun 23, 2023

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.11.0

unknown

The ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the error parameter in versions up to, and including, 4.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

Affected:
up to 4.11.0
Fixed in:
4.11.0
Disclosed:
Jun 23, 2023

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.5.5

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.

Affected:
up to 4.5.5
Fixed in:
4.5.5
Disclosed:
May 3, 2023

CVE-2023-23830 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.5.5

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.

Affected:
up to 4.5.5
Fixed in:
4.5.5
Disclosed:
May 3, 2023

CVE-2023-23820 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.5.4

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.3 versions.

Affected:
up to 4.5.4
Fixed in:
4.5.4
Disclosed:
Apr 6, 2023

CVE-2023-23996 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.5.5

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin <= 4.5.3 versions.

Affected:
up to 4.5.5
Fixed in:
4.5.5
Disclosed:
Mar 29, 2023

CVE-2022-47444 on NVD →

ProfilePress <= 4.5.3 - Unauthenticated Cross-Site Scripting

high

The ProfilePress plugin for WordPress is vulnerable to Cross-Site Scripting via $data['name'] parameter in versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute when...

CVSS:
7.2
Affected:
up to 4.5.3
Fixed in:
4.5.4
Disclosed:
Mar 27, 2023

CVE-2022-47444 on NVD →

ProfilePress <= 4.5.4 - Unauthenticated Stored Cross-Site Scripting

high

The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous parameters in versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute w...

CVSS:
7.2
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
Feb 21, 2023

CVE-2023-23830 on NVD →

ProfilePress <= 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes

medium

The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and a...

CVSS:
6.4
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
Feb 20, 2023

CVE-2023-23820 on NVD →

ProfilePress <= 4.5.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scr...

CVSS:
5.5
Affected:
up to 4.5.3
Fixed in:
4.5.4
Disclosed:
Jan 20, 2023

CVE-2023-23996 on NVD →

ProfilePress <= 4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_url’ parameter in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissi...

CVSS:
5.5
Affected:
up to 4.5.0
Fixed in:
4.5.1
Disclosed:
Dec 23, 2022

CVE-2022-4697 on NVD →

ProfilePress <= 4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Form Settings

medium

The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arb...

CVSS:
5.5
Affected:
up to 4.5.0
Fixed in:
4.5.1
Disclosed:
Dec 23, 2022

CVE-2022-4698 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.5.1

unknown

[en] The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_url’ parameter in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level per...

Affected:
up to 4.5.1
Fixed in:
4.5.1
Disclosed:
Dec 23, 2022

CVE-2022-4697 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.5.1

unknown

[en] The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to injec...

Affected:
up to 4.5.1
Fixed in:
4.5.1
Disclosed:
Dec 23, 2022

CVE-2022-4698 on NVD →

ProfilePress <= 4.3.2 - Authenticated (Admin+) PHP Object Injection

medium

The ProfilePress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.2 via deserialization of untrusted input in functions like 'get_form_meta'. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain...

CVSS:
6.6
Affected:
up to 4.3.2
Fixed in:
4.4.0
Disclosed:
Dec 14, 2022

CVE-2022-45083 on NVD →

WordPress Membership, User Registration, Login Form, User Profile & Restrict Content Plugin – ProfilePress <= 3.2.15 - Reflected Cross-Site Scripting

medium

The WordPress Membership, User Registration, Login Form, User Profile & Restrict Content Plugin – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'filter1' parameter in versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes...

CVSS:
6.1
Affected:
up to 3.2.15
Fixed in:
3.2.16
Disclosed:
Jul 22, 2022

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 3.2.16

unknown

The WordPress Membership, User Registration, Login Form, User Profile & Restrict Content Plugin – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'filter1' parameter in versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes...

Affected:
up to 3.2.16
Fixed in:
3.2.16
Disclosed:
Jul 22, 2022

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 3.2.3

unknown

[en] The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Dec 13, 2021

CVE-2021-24955 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 3.2.3

unknown

[en] The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Dec 13, 2021

CVE-2021-24954 on NVD →

ProfilePress <= 3.2.2 - Reflected Cross-Site Scripting via ppress_cc_data Parameter

medium

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Nov 15, 2021

CVE-2021-24954 on NVD →

ProfilePress <= 3.2.2 - Reflected Cross-Site Scripting

medium

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Nov 15, 2021

CVE-2021-24955 on NVD →

Paid Membership, User Registration, User Profile & Restrict Content Plugin – ProfilePress <= 3.1.10 - Unauthenticated Cross-Site Scripting

high

The User Registration, User Profile, Login & Membership &#8211; ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST...

CVSS:
7.2
Affected:
up to 3.1.10
Fixed in:
3.1.11
Disclosed:
Aug 9, 2021

CVE-2021-24522 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 3.1.11

unknown

[en] The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST a...

Affected:
up to 3.1.11
Fixed in:
3.1.11
Disclosed:
Aug 9, 2021

CVE-2021-24522 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 3.1.8

unknown

[en] The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 did not sanitise or escape some of its settings before saving them and outputting them back in the page, allowing high privilege users such as admin to set JavaScript payloads in them eve...

Affected:
up to 3.1.8
Fixed in:
3.1.8
Disclosed:
Aug 2, 2021

CVE-2021-24450 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] >= 3.0.0 - <= 3.1.3

unknown

[en] A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

Affected:
3.0.0 – 3.1.3
Fixed in:
3.1.3
Disclosed:
Jul 7, 2021

CVE-2021-34624 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] >= 3.0.0 - <= 3.1.3

unknown

[en] A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

Affected:
3.0.0 – 3.1.3
Fixed in:
3.1.3
Disclosed:
Jul 7, 2021

CVE-2021-34623 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] >= 3.0.0 - <= 3.1.3

unknown

[en] A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects versions 3.0.0 - 3.1.3. .

Affected:
3.0.0 – 3.1.3
Fixed in:
3.1.3
Disclosed:
Jul 7, 2021

CVE-2021-34622 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] >= 3.0.0 - <= 3.1.3

unknown

[en] A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .

Affected:
3.0.0 – 3.1.3
Fixed in:
3.1.3
Disclosed:
Jul 7, 2021

CVE-2021-34621 on NVD →

ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation

critical

A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects versions 3.0.0 - 3.1.3. .

CVSS:
9.8
Affected:
3.0.0 – 3.1.3
Fixed in:
3.1.4
Disclosed:
Jun 28, 2021

CVE-2021-34622 on NVD →

ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload

critical

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3.

CVSS:
9.8
Affected:
3.0.0 – 3.1.3
Fixed in:
3.1.4
Disclosed:
Jun 28, 2021

CVE-2021-34624 on NVD →

User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) 3.0.0 - 3.1.3 - Unauthenticated Privilege Escalation

critical

A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .

CVSS:
9.8
Affected:
3.0.0 – 3.1.3
Fixed in:
3.1.4
Disclosed:
Jun 28, 2021

CVE-2021-34621 on NVD →

User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) 3.0.0 - 3.1.3 - Unauthenticated Privilege Escalation

critical

A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

CVSS:
9.8
Affected:
3.0.0 – 3.1.3
Fixed in:
3.1.4
Disclosed:
Jun 28, 2021

CVE-2021-34623 on NVD →

ProfilePress <= 3.1.7 - Authenticated Stored Cross-Site Scripting

medium

The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 did not sanitise or escape some of its settings before saving them and outputting them back in the page, allowing high privilege users such as admin to set JavaScript payloads in them even whe...

CVSS:
5.5
Affected:
up to 3.1.8
Fixed in:
3.1.8
Disclosed:
Jun 28, 2021

CVE-2021-24450 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 4.16.5

unknown
Affected:
up to 4.16.5
Fixed in:
4.16.5

CVE-2025-8878 on NVD →

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Restrict Content – ProfilePress [wp-user-avatar] < 3.1.11

unknown

The plugin changelog stated multiple vulnerability fixes, including Cross-Site Scripting (XSS), SQL escaping and redirection validation. The changelog stated: - Fixed missing sql unescaping in member directory search. - Validate redirect_to urls to prevent redirect to another site. - XSS fix by escaping variabl...

Affected:
up to 3.1.11
Fixed in:
3.1.11

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database