properfraction Vulnerabilities and Affected Products
Vulnerabilities associated with profilepress.
Products
Clear product- Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress20 vulnerabilities
- profilepress6 vulnerabilities
- MailOptin3 vulnerabilities
- kk Star Ratings – Rate Post & Collect User Feedbacks2 vulnerabilities
- CrawlWP SEO1 vulnerability
- CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor1 vulnerability
- MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc.1 vulnerability
- Rate My Post – Star Rating Plugin by FeedbackWP1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-41556MEDIUM | WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerabilitySubscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions. CWE-79Jun 15, 2026 | CVSS6.5v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-50882MEDIUM | WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerabilityMissing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through <= 4.13.2. CWE-862Dec 9, 2024 | CVSS5.3v3.1 | EPSS0.49% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-34624CRITICAL | ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader ComponentA vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. . | CVSS9.8v3.1 | EPSS6.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-34621CRITICAL | ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege EscalationA vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. . | CVSS9.8v3.1 | EPSS68.9% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-34623CRITICAL | ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader ComponentA vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. . CWE-434Jul 7, 2021 | CVSS9.8v3.1 | EPSS2.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-34622CRITICAL | ProfilePress 3.0 - 3.1.3 - Authenticated Privilege EscalationA vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects versions 3.0.0 - 3.1.3. . | CVSS9.8v3.1 | EPSS4.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |