Authentication vulnerability in ProfilePress Pro 4.11.1

The ProfilePress Pro plugin for WordPress has a security issue that allows unauthorized users to bypass authentication. This can happen because the plugin does not properly check the user’s information when using social login. This means that someone without an account on the site can log in as any existing user, like an administrator, if they know the email address and the user does not already have an account with the social login service.

Detected in:

ProfilePress Pro fixed vulnerable versions: >= * <= 4.11.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.