← WordPress Vulnerabilities
WordPress security by component

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content is a WordPress component with 25 published CVE records in this archive. The latest tracked vulnerability was published Feb 13, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: profilepress

CVE-2024-13121: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content: Cross-site scripting

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedFeb 13, 2025
Safe version guidanceSee mitigation notes
Safe version
Feb 13, 2025 CVE-2024-13121
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVDPending
Feb 13, 2025 CVE-2024-13120
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Feb 13, 2025 CVE-2024-13119
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Dec 12, 2024 CVE-2024-10518
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Dec 12, 2024 CVE-2024-10517
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Dec 09, 2024 CVE-2023-41953
ProfilePress: A security weakness
ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 09, 2024 CVE-2023-50882
ProfilePress: A security weakness
ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 27, 2024 CVE-2024-11083
ProfilePress: Sensitive information exposure
ProfilePress is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Oct 23, 2024 CVE-2024-9947
ProfilePress Pro: Privilege escalation or authentication bypass
ProfilePress Pro is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.1
NVD9.8
May 23, 2024 CVE-2024-2861
ProfilePress: Cross-site scripting
ProfilePress is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-2867
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 10, 2024 CVE-2024-3210
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1535
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2024-1409
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 29, 2024 CVE-2024-1570
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 29, 2024 CVE-2024-1408
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 05, 2024 CVE-2024-1046
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 23, 2022 CVE-2022-4698
ProfilePress: Cross-site scripting
ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD4.8
Dec 23, 2022 CVE-2022-4697
ProfilePress: Cross-site scripting
ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD4.8
Aug 09, 2021 CVE-2021-24522
User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar): Cross-site scripting
User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 02, 2021 CVE-2021-24450
User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar): Cross-site scripting
User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jul 07, 2021 CVE-2021-34624
file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress: A security weakness
file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Jul 07, 2021 CVE-2021-34623
image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress: A security weakness
image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Jul 07, 2021 CVE-2021-34622
user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress: A security weakness
user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD8.8
Jul 07, 2021 CVE-2021-34621
user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress: A security weakness
user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8