← WordPress Vulnerabilities
WordPress security by component

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress provides tools for user registration, login, profiles, membership plans, payments, and restricted WordPress content.

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress (profilepress) is a WordPress plugin with 26 published CVE records in this archive. The latest tracked vulnerability was published Aug 21, 2026; the highest published CVSS base score is 9.8.

Plugin slug: profilepress

CVE-2026-19848: ProfilePress executes attacker-supplied shortcodes from public profile fields

ProfilePress before 4.17.1 does not strip shortcodes from two profile fields before rendering them on public pages. An unauthenticated attacker can store a shortcode in those fields; when the affected page is rendered, WordPress executes it and discloses a chosen user's email address, login name and registration date.

PublishedAug 21, 2026
Known safe version4.17.1
Published vulnerabilities for profilepress
Safe version
Aug 21, 2026 CVE-2026-19848
ProfilePress executes attacker-supplied shortcodes from public profile fields
ProfilePress before 4.17.1 does not strip shortcodes from two profile fields before rendering them on public pages. An unauthenticated attacker can store a shortcode in those fields; when the affected page is rendered, WordPress executes it and discloses a chosen user's email address, login name and registration date.
4.17.1
CVE6.5
NVDPending
Feb 13, 2025 CVE-2024-13121
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVDPending
Feb 13, 2025 CVE-2024-13120
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Feb 13, 2025 CVE-2024-13119
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Dec 12, 2024 CVE-2024-10518
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Dec 12, 2024 CVE-2024-10517
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Dec 09, 2024 CVE-2023-41953
ProfilePress: A security weakness
ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 09, 2024 CVE-2023-50882
ProfilePress: A security weakness
ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 27, 2024 CVE-2024-11083
ProfilePress: Sensitive information exposure
ProfilePress is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Oct 23, 2024 CVE-2024-9947
ProfilePress Pro: Privilege escalation or authentication bypass
ProfilePress Pro is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.1
NVD9.8
May 23, 2024 CVE-2024-2861
ProfilePress: Cross-site scripting
ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-2867
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 10, 2024 CVE-2024-3210
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1535
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1409
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 29, 2024 CVE-2024-1570
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 29, 2024 CVE-2024-1408
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 05, 2024 CVE-2024-1046
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 23, 2022 CVE-2022-4698
ProfilePress: Cross-site scripting
ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD4.8
Dec 23, 2022 CVE-2022-4697
ProfilePress: Cross-site scripting
ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD4.8
Aug 09, 2021 CVE-2021-24522
User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar): Cross-site scripting
User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Aug 02, 2021 CVE-2021-24450
User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar): Cross-site scripting
User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
Jul 07, 2021 CVE-2021-34624
file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress: A security weakness
file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Jul 07, 2021 CVE-2021-34623
image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress: A security weakness
image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Jul 07, 2021 CVE-2021-34622
user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress: A security weakness
user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD8.8
Jul 07, 2021 CVE-2021-34621
user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress: A security weakness
user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8