Showing 6 vulnerabilities on this page for profilepress

Signals CISA KEV Ransomware Nuclei
properfraction vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability

Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions.

CWE-79Jun 15, 2026
CVSS6.5v3.1EPSS0.205%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through <= 4.13.2.

CWE-862Dec 9, 2024
CVSS5.3v3.1EPSS0.49%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Component

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

CWE-434Jul 7, 20211 related artifact
CVSS9.8v3.1EPSS6.74%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation

A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .

CWE-269CWE-306Jul 7, 20211 related artifact
CVSS9.8v3.1EPSS68.9%PoCs4SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader Component

A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

CWE-434Jul 7, 2021
CVSS9.8v3.1EPSS2.1%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalation

A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects versions 3.0.0 - 3.1.3. .

CWE-269Jul 7, 20211 related artifact
CVSS9.8v3.1EPSS4.12%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX