CVE-2026-3445
- EPSS 0.23%
- Veröffentlicht 04.04.2026 08:25:20
- Zuletzt bearbeitet 21.07.2026 19:10:00
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This...
CVE-2026-3453
- EPSS 0.38%
- Veröffentlicht 11.03.2026 02:22:46
- Zuletzt bearbeitet 22.04.2026 21:27:27
The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to missing ownership validation on the change_plan_sub_id parameter in the process_checkout() function....
CVE-2025-13642
- EPSS 0.47%
- Veröffentlicht 09.12.2025 15:23:48
- Zuletzt bearbeitet 07.10.2026 20:10:01
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.7 due to insuffic...
CVE-2025-8878
- EPSS 0.44%
- Veröffentlicht 16.08.2025 11:11:24
- Zuletzt bearbeitet 15.04.2026 00:35:42
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.4. This is du...
CVE-2024-13121
- EPSS 0.31%
- Veröffentlicht 13.02.2025 06:15:21
- Zuletzt bearbeitet 21.05.2025 18:56:21
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to per...
CVE-2024-13120
- EPSS 0.31%
- Veröffentlicht 13.02.2025 06:15:20
- Zuletzt bearbeitet 21.05.2025 18:57:54
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to per...
CVE-2024-13119
- EPSS 0.35%
- Veröffentlicht 13.02.2025 06:15:20
- Zuletzt bearbeitet 21.05.2025 19:00:15
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to per...
CVE-2024-10518
- EPSS 0.34%
- Veröffentlicht 12.12.2024 06:15:20
- Zuletzt bearbeitet 17.05.2025 02:28:54
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Membership Plan settings, which could allow high privilege users such...
CVE-2024-10517
- EPSS 0.34%
- Veröffentlicht 12.12.2024 06:15:20
- Zuletzt bearbeitet 17.05.2025 02:28:18
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Drag & Drop Builder fields, which could allow high privilege users su...
CVE-2023-41953
- EPSS 0.4%
- Veröffentlicht 09.12.2024 14:15:08
- Zuletzt bearbeitet 09.06.2025 19:29:02
Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1.