CVE-2026-96518
- EPSS -
- Veröffentlicht 09.10.2026 10:00:16
- Zuletzt bearbeitet 09.10.2026 16:17:33
Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.17.3.
CVE-2026-96337
- EPSS -
- Veröffentlicht 09.10.2026 10:00:16
- Zuletzt bearbeitet 09.10.2026 13:20:48
Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.17.3.
CVE-2026-92551
- EPSS 0.22%
- Veröffentlicht 03.10.2026 03:25:43
- Zuletzt bearbeitet 06.10.2026 15:04:52
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versio...
CVE-2026-92536
- EPSS 0.63%
- Veröffentlicht 03.10.2026 03:25:43
- Zuletzt bearbeitet 06.10.2026 15:04:52
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_us...
CVE-2026-85658
- EPSS 0.36%
- Veröffentlicht 19.09.2026 07:43:19
- Zuletzt bearbeitet 21.09.2026 13:33:33
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to ...
CVE-2026-66047
- EPSS 0.54%
- Veröffentlicht 31.08.2026 14:46:41
- Zuletzt bearbeitet 08.09.2026 20:18:59
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token ...
CVE-2026-18385
- EPSS 0.32%
- Veröffentlicht 16.08.2026 04:24:50
- Zuletzt bearbeitet 20.08.2026 12:48:10
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.19. This is d...
CVE-2026-13352
- EPSS 0.58%
- Veröffentlicht 17.07.2026 03:43:41
- Zuletzt bearbeitet 17.07.2026 16:17:13
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_t...
CVE-2026-41556
- EPSS 0.21%
- Veröffentlicht 15.06.2026 20:18:31
- Zuletzt bearbeitet 15.06.2026 21:24:32
Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions.
CVE-2026-3309
- EPSS 0.41%
- Veröffentlicht 04.04.2026 11:16:14
- Zuletzt bearbeitet 24.07.2026 22:10:00
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.11. This is due t...