Extension WordPress
Vulnérabilités Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress, page 2
Cette page rassemble les failles publiées pour Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
44 fiches
ProfilePress <= 4.14.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's login-password shortcode in all versions up to, and including,…
*-4.14.4
4.15.0
19/02/2024
ProfilePress <= 4.14.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edit-profile-text-box shortcode in all versions up to, and including,…
*-4.14.4
4.15.0
19/02/2024
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 – Unauthenticated Stored Cross-Site Scripting
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 4.14.4…
*-4.14.4
4.15.0
19/02/2024
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'reg-number-field' shortcode in all versions up to, and including,…
*-4.14.3
4.14.4
01/02/2024
ProfilePress <= 4.13.2 – Information Disclosure via Debug Log
The ProfilePress plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.13.2 via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may…
*-4.13.2
4.13.3
02/10/2023
ProfilePress <= 4.13.1 Cross-Site Request Forgery via 'admin_notice'
The ProfilePress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.13.1. This is due to missing or incorrect nonce validation on the 'admin_notice' function. This makes it possible for unauthenticated attackers…
[*, 4.13.2)
4.13.2
09/09/2023
ProfilePress <= 4.13.1 – Limited Privilege Escalation via 'acceptable_defined_roles'
The ProfilePress plugin for WordPress is vulnerable to limited privilege escalation in versions up to, and including, 4.13.1 via the 'acceptable_defined_roles' function due to incomplete validation on a user controlled key. This can allow unauthenticated attackers to elevate…
[*, 4.13.2)
4.13.2
09/09/2023
ProfilePress <= 4.10.3 – Reflected Cross-Site Scripting via error message
The ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the error parameter in versions up to, and including, 4.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
[*, 4.11.0)
4.11.0
23/06/2023
ProfilePress <= 4.5.3 – Unauthenticated Cross-Site Scripting
The ProfilePress plugin for WordPress is vulnerable to Cross-Site Scripting via $data['name'] parameter in versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-4.5.3
4.5.4
27/03/2023
ProfilePress <= 4.5.4 – Unauthenticated Stored Cross-Site Scripting
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous parameters in versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-4.5.4
4.5.5
21/02/2023
ProfilePress <= 4.5.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
*-4.5.4
4.5.5
20/02/2023
ProfilePress <= 4.5.3 – Authenticated (Administrator+) Stored Cross-Site Scripting
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…
*-4.5.3
4.5.4
20/01/2023
ProfilePress <= 4.5.0 – Authenticated (Administrator+) Stored Cross-Site Scripting via Form Settings
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-4.5.0
4.5.1
23/12/2022
ProfilePress <= 4.5.0 – Authenticated (Administrator+) Stored Cross-Site Scripting
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_url’ parameter in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-4.5.0
4.5.1
23/12/2022
ProfilePress <= 4.3.2 – Authenticated (Admin+) PHP Object Injection
The ProfilePress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.2 via deserialization of untrusted input in functions like 'get_form_meta'. This allows administrator-level attackers to inject a PHP Object. No POP…
*-4.3.2
4.4.0
14/12/2022
WordPress Membership, User Registration, Login Form, User Profile & Restrict Content Plugin – ProfilePress <= 3.2.15 – Reflected Cross-Site Scripting
The WordPress Membership, User Registration, Login Form, User Profile & Restrict Content Plugin – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'filter1' parameter in versions up to, and including, 3.2.15 due to insufficient…
*-3.2.15
3.2.16
22/07/2022
ProfilePress <= 3.2.2 – Reflected Cross-Site Scripting via ppress_cc_data Parameter
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site…
[*, 3.2.3)
3.2.3
15/11/2021
ProfilePress <= 3.2.2 – Reflected Cross-Site Scripting
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
[*, 3.2.3)
3.2.3
15/11/2021
Paid Membership, User Registration, User Profile & Restrict Content Plugin – ProfilePress <= 3.1.10 – Unauthenticated Cross-Site Scripting
The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to…
*-3.1.10
3.1.11
09/08/2021
ProfilePress 3.0 – 3.1.3 – Unauthenticated Privilege Escalation
A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue…
3.0.0-3.1.3
3.1.4
28/06/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.