WordPress security by component
ProfilePress
Plugin description
ProfilePress is a WordPress component with 17 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
wp-user-avatarLatest vulnerability
CVE-2026-12497: ProfilePress role parsing permits elevated public registration
ProfilePress before 4.16.18 can render a restricted reg-select-role field while RegistrationAuth::acceptable_defined_roles() parses its options differently. For configurations using valid quoting or hyphenated role names that the old parser misses, the server falls back to all editable non-administrator roles; an unauthenticated pp_ajax_signup or front-end registration submission can therefore supply reg_select_role=editor or author even when the form did not offer it.
| Safe version |
|
||
|---|---|---|---|
| Jul 24, 2026 |
CVE-2026-12497
ProfilePress role parsing permits elevated public registration
ProfilePress before 4.16.18 can render a restricted reg-select-role field while RegistrationAuth::acceptable_defined_roles() parses its options differently. For configurations using valid quoting or hyphenated role names that the old parser misses, the server falls back to all editable non-administrator roles; an unauthenticated pp_ajax_signup or front-end registration submission can therefore supply reg_select_role=editor or author even when the form did not offer it.
|
4.16.18 |
CVE7.4
NVDPending
|
| Jul 17, 2026 |
CVE-2026-13352
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Dangerous file upload
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by dangerous file upload. Exploitation requires at least author-level access. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 4.16.18.
|
> 4.16.18 |
CVE8.8
NVDPending
|
| Jun 27, 2026 |
CVE-2026-10820
ProfilePress: A security weakness
ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.16.17.
|
4.16.17 |
CVE8.1
NVDPending
|
| Jun 15, 2026 |
CVE-2026-41556
ProfilePress: Cross-site scripting
ProfilePress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.16.13.
|
4.16.14 |
CVE6.5
NVDPending
|
| Apr 15, 2026 |
CVE-2026-4949
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: A security weakness
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.16.12.
|
> 4.16.12 |
CVE4.3
NVDPending
|
| Mar 11, 2026 |
CVE-2026-3453
ProfilePress: A security weakness
ProfilePress is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Dec 09, 2025 |
CVE-2025-13642
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: A security weakness
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Aug 16, 2025 |
CVE-2025-8878
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: A security weakness
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| May 17, 2024 |
CVE-2023-41954
ProfilePress: Privilege escalation or authentication bypass
ProfilePress is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.6
NVDPending
|
| Mar 13, 2024 |
CVE-2024-1806
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 29, 2024 |
CVE-2024-1519
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD6.1
|
| Jan 19, 2024 |
CVE-2022-45083
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Code execution
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE6.6
NVD7.2
|
| Nov 30, 2023 |
CVE-2023-44150
Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: A security weakness
Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| May 03, 2023 |
CVE-2023-23830
Wp User Avatar: Cross-site scripting
Wp User Avatar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| May 03, 2023 |
CVE-2023-23820
Wp User Avatar: Cross-site scripting
Wp User Avatar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Apr 06, 2023 |
CVE-2023-23996
Wp User Avatar: Cross-site scripting
Wp User Avatar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Mar 29, 2023 |
CVE-2022-47444
Wp User Avatar: Cross-site scripting
Wp User Avatar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|