Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Access violation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 4.13.2

    Fixed

    The ProfilePress plugin for WordPress has a security vulnerability in versions up to 4.13.2. Unauthenticated attackers could access debug logs without any protection, which could contain sensitive in...

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 4.13.2

    Fixed

    The ProfilePress plugin for WordPress has a security vulnerability that could potentially affect versions up to, and including, version 4.13.1. This security issue is due to the lack of, or incorrect...

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 4.13.2

    Fixed

    The ProfilePress plugin for WordPress, up to version 4.13.2, has an issue that can allow unauthenticated attackers to gain a higher level of access on the website during user-registration. This is po...

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 4.11.0

    Fixed

    The ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting up to version 4.10.3. This means that unauthenticated attackers can inject malicious web scripts into pages that ...

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 3.2.3

    Fixed

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 3.2.15

    Fixed

    The WordPress Membership, User Registration, Login Form, User Profile & Restrict Content Plugin – ProfilePress is vulnerable to an attack called Reflected Cross-Site Scripting. This type of att...

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 4.5.4

    Fixed

    The ProfilePress plugin for WordPress has a security vulnerability that affects versions up to and including 4.5.4. If someone uses this version

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 4.5.3

    Fixed

    The ProfilePress plugin for WordPress has a security vulnerability that allows unauthenticated attackers to inject malicious web scripts on pages. This vulnerability affects versions up to 4.5.3 and i...

    Read More
  • Access violation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 3.1.3

    Fixed

    The ProfilePress WordPress plugin had a problem where users were able to gain higher privileges than they should have when editing their profile. This problem existed in versions 3.0.0 - 3.1.3 of the ...

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 4.5.3

    Fixed

    The ProfilePress plugin for WordPress can be a security risk in certain cases. If your WordPress website uses ProfilePress version 4.5.3 or earlier

    Read More
  • Output validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 4.3.2

    Fixed

    The ProfilePress plugin for WordPress has a security issue that affects versions up to 4.3.2. An attacker with administrator access can exploit this issue to inject a malicious code. If other plugins ...

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 3.2.3

    Fixed

    Read More
  • Access violation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 3.1.3

    Fixed

    The ProfilePress WordPress plugin had a problem in its user registration system that made it possible for people to register as administrators on websites. This issue was present in versions 3.0.0 - 3...

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 3.1.3

    Fixed

    A security issue was found in the ProfilePress WordPress plugin which could allow users to upload any type of file when creating or updating their profile. This vulnerability affects versions 3.0.0 to...

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 3.1.10

    Fixed

    The User Registration

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 3.1.3

    Fixed

    A security problem was discovered in a part of the ProfilePress WordPress plugin that allows people to upload images. This issue affects versions 3.0.0 to 3.1.3 of the plugin

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 4.5.4

    Fixed

    The ProfilePress plugin for WordPress is not secure for versions up to 4.5.4. People with contributor-level and higher permissions can inject malicious web scripts into pages. These scripts can be act...

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 4.5.0

    Fixed

    The ProfilePress plugin for WordPress is not secure for versions up to 4.5.0. This means that someone with administrator privileges who has access to the plugin could inject malicious code into the we...

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 4.5.0

    Fixed

    The ProfilePress plugin for WordPress has a security flaw that allows people with administrator-level permissions (and above) to inject malicious web scripts into pages. This flaw only affects multi-s...

    Read More
  • Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 3.1.8

    Fixed

    Read More