← WordPress Vulnerabilities
WordPress security by component

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Apr 04, 2026; the highest CVE/CNA score is 7.1.

Plugin slug: registration-form-login-form-user-profile-restrict-content-profilepress

CVE-2026-3309: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: A security weakness

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.16.11.

PublishedApr 04, 2026
Known safe version> 4.16.11
Safe version
Apr 04, 2026 CVE-2026-3309
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: A security weakness
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.16.11.
> 4.16.11
CVE6.5
NVDPending
Apr 04, 2026 CVE-2026-3445
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: A security weakness
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.16.11.
> 4.16.11
CVE7.1
NVDPending