Softver
profilepress
Aggregate across all detected versions
Ukupno hostova
0
distinct hosts
Versions Seen
0
Countries
0
Poznate CVE ranjivosti
34
known CVEs
Top države
No geolocated hosts.
Top ASN-ovi
No attributed hosts.
CVE podudaranja
| CVE | CVSS | Severity | Summary |
|---|---|---|---|
| CVE-2021-34621 | 9.8 | N/A | A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible fo... |
| CVE-2021-34622 | 9.8 | N/A | A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible f... |
| CVE-2021-34623 | 9.8 | N/A | A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for user... |
| CVE-2021-34624 | 9.8 | N/A | A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users... |
| CVE-2023-41954 | 8.6 | N/A | Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a t... |
| CVE-2024-9947 | 8.1 | N/A | The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verif... |
| CVE-2023-44150 | 7.5 | N/A | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, L... |
| CVE-2022-47444 | 7.1 | N/A | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, Use... |
| CVE-2023-23830 | 7.1 | N/A | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions. |
| CVE-2022-45083 | 6.6 | N/A | Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Prof... |
| CVE-2023-23820 | 6.5 | N/A | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions. |
| CVE-2024-1519 | 6.5 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to... |
| CVE-2024-1046 | 6.4 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to... |
| CVE-2024-1408 | 6.4 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to... |
| CVE-2024-1409 | 6.4 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to... |
| CVE-2024-1535 | 6.4 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to... |
| CVE-2024-1570 | 6.4 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to... |
| CVE-2024-1806 | 6.4 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to... |
| CVE-2024-2861 | 6.4 | N/A | The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ProfilePress User Panel widget in all versions up to, and including,... |
| CVE-2024-2867 | 6.4 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to... |
| CVE-2024-3210 | 6.4 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to... |
| CVE-2021-24522 | 6.1 | N/A | The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/regist... |
| CVE-2023-23996 | 5.9 | N/A | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.3 versions. |
| CVE-2022-4697 | 5.5 | N/A | The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_url’ parameter in versions up to, and in... |
| CVE-2022-4698 | 5.5 | N/A | The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions up to, and including, 4.5.0 due to insuff... |
| CVE-2023-41953 | 5.3 | N/A | Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1. |
| CVE-2023-50882 | 5.3 | N/A | Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This i... |
| CVE-2024-11083 | 5.3 | N/A | The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress core searc... |
| CVE-2021-24450 | 4.8 | N/A | The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 did not sanitise or escape some... |
| CVE-2024-10517 | 4.8 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise an... |
| CVE-2024-10518 | 4.8 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise an... |
| CVE-2024-13119 | 4.8 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise an... |
| CVE-2024-13120 | 4.8 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise an... |
| CVE-2024-13121 | 3.5 | N/A | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise an... |