Profilepress develops user authentication and membership management plugins, particularly LoginWP and its user registration and profile components, which are deployed across WordPress-based web applications. The recurring vulnerability signal centers on input-handling weaknesses in web-facing forms, notably cross-site scripting and cross-site request forgery, which are characteristic of form-processing and session-management surfaces in web plugins. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Profilepress over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15115HIGH The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF. | Aug 16, 2019 | 8.8 | 27 | NO | NO |
CVE-2021-24939MEDIUM The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login_url and rul_logout_url parameter before outputting them bac | Dec 6, 2021 | 6.1 | 22 | NO | NO |
CVE-2021-24955MEDIUM The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before | Dec 13, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-24954MEDIUM The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an | Dec 13, 2021 | 6.1 | 21 | NO | NO |
CVE-2016-10925MEDIUM The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs. | Aug 22, 2019 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Profilepress.
Media articles that mention a CVE ID that affects a product developed by Profilepress — matched by CVE ID, not by vendor name.