← WordPress Vulnerabilities
WordPress security by component

ProfilePress

ProfilePress is a WordPress component with 17 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: wp-user-avatar

CVE-2026-12497: ProfilePress role parsing permits elevated public registration

ProfilePress before 4.16.18 can render a restricted reg-select-role field while RegistrationAuth::acceptable_defined_roles() parses its options differently. For configurations using valid quoting or hyphenated role names that the old parser misses, the server falls back to all editable non-administrator roles; an unauthenticated pp_ajax_signup or front-end registration submission can therefore supply reg_select_role=editor or author even when the form did not offer it.

PublishedJul 24, 2026
Known safe version4.16.18
Safe version
Jul 24, 2026 CVE-2026-12497
ProfilePress role parsing permits elevated public registration
ProfilePress before 4.16.18 can render a restricted reg-select-role field while RegistrationAuth::acceptable_defined_roles() parses its options differently. For configurations using valid quoting or hyphenated role names that the old parser misses, the server falls back to all editable non-administrator roles; an unauthenticated pp_ajax_signup or front-end registration submission can therefore supply reg_select_role=editor or author even when the form did not offer it.
4.16.18
CVE7.4
NVDPending
Jul 17, 2026 CVE-2026-13352
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Dangerous file upload
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by dangerous file upload. Exploitation requires at least author-level access. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 4.16.18.
> 4.16.18
CVE8.8
NVDPending
Jun 27, 2026 CVE-2026-10820
ProfilePress: A security weakness
ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.16.17.
4.16.17
CVE8.1
NVDPending
Jun 15, 2026 CVE-2026-41556
ProfilePress: Cross-site scripting
ProfilePress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.16.13.
4.16.14
CVE6.5
NVDPending
Apr 15, 2026 CVE-2026-4949
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: A security weakness
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.16.12.
> 4.16.12
CVE4.3
NVDPending
Mar 11, 2026 CVE-2026-3453
ProfilePress: A security weakness
ProfilePress is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.1
NVDPending
Dec 09, 2025 CVE-2025-13642
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: A security weakness
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Aug 16, 2025 CVE-2025-8878
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: A security weakness
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
May 17, 2024 CVE-2023-41954
ProfilePress: Privilege escalation or authentication bypass
ProfilePress is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.6
NVDPending
Mar 13, 2024 CVE-2024-1806
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 29, 2024 CVE-2024-1519
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Cross-site scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD6.1
Jan 19, 2024 CVE-2022-45083
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: Code execution
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE6.6
NVD7.2
Nov 30, 2023 CVE-2023-44150
Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: A security weakness
Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
May 03, 2023 CVE-2023-23830
Wp User Avatar: Cross-site scripting
Wp User Avatar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
May 03, 2023 CVE-2023-23820
Wp User Avatar: Cross-site scripting
Wp User Avatar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Apr 06, 2023 CVE-2023-23996
Wp User Avatar: Cross-site scripting
Wp User Avatar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Mar 29, 2023 CVE-2022-47444
Wp User Avatar: Cross-site scripting
Wp User Avatar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1