The ProfilePress plugin for WordPress is not secure for versions up to 4.5.4. People with contributor-level and higher permissions can inject malicious web scripts into pages. These scripts can be activated just by viewing the page
The ProfilePress plugin for WordPress is not secure for versions up to 4.5.4. People with contributor-level and higher permissions can inject malicious web scripts into pages. These scripts can be activated just by viewing the page
This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!
Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:
> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21
Is this information incorrect? Please leave us a message.