Input validation vulnerability in Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress 3.2.15

The WordPress Membership, User Registration, Login Form, User Profile & Restrict Content Plugin – ProfilePress is vulnerable to an attack called Reflected Cross-Site Scripting. This type of attack can be used by an unauthenticated attacker to inject malicious web scripts into pages that can then be executed if the user is tricked into performing an action like clicking on a link. The vulnerability is present in versions up to, and including, 3.2.15 and is caused by insufficient input sanitization and output escaping.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.