CVE-2024-1408
- EPSS 0.24%
- Veröffentlicht 29.02.2024 01:43:49
- Zuletzt bearbeitet 22.01.2025 16:44:00
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edit-profile-text-box shortcode in all versio...
CVE-2024-1046
- EPSS 0.24%
- Veröffentlicht 05.02.2024 22:16:06
- Zuletzt bearbeitet 21.11.2024 08:49:40
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'reg-number-field' shortcode in all versions up...
CVE-2022-45083
- EPSS 0.27%
- Veröffentlicht 19.01.2024 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:28:44
Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plugin, Ecommerce...
CVE-2023-44150
- EPSS 0.62%
- Veröffentlicht 30.11.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:25:19
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membersh...
CVE-2023-23830
- EPSS 0.24%
- Veröffentlicht 03.05.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:54
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
CVE-2023-23820
- EPSS 0.26%
- Veröffentlicht 03.05.2023 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:46:53
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
CVE-2023-23996
- EPSS 0.24%
- Veröffentlicht 06.04.2023 08:15:07
- Zuletzt bearbeitet 21.11.2024 07:47:13
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.3 versions.
CVE-2022-47444
- EPSS 0.24%
- Veröffentlicht 29.03.2023 13:15:07
- Zuletzt bearbeitet 21.11.2024 07:31:58
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin <= 4.5.3 versions.
CVE-2022-4698
- EPSS 0.29%
- Veröffentlicht 23.12.2022 16:15:13
- Zuletzt bearbeitet 21.11.2024 07:35:45
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...
CVE-2022-4697
- EPSS 0.29%
- Veröffentlicht 23.12.2022 16:15:13
- Zuletzt bearbeitet 21.11.2024 07:35:45
The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_url’ parameter in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it p...