Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Properfraction

First CVE: Jul 7, 2021Active for: 5 yearsTotal CVEs: 36
35.1
VTI Score
Medium

Properfraction maintains a narrow portfolio of WordPress plugins and access-control extensions that, despite modest product breadth, serve a well-represented niche in the WordPress ecosystem. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a corresponding tendency toward public exploit availability, reflecting the web-application nature of the product line and the appeal of WordPress plugins as attack vectors. The exposure recurs across products such as ProfilePress and Admin Bar & Dashboard Access Control, clustering around cross-site scripting, privilege management, information disclosure, and authorization weaknesses that are characteristic of plugin-based access and user-management functionality. Defenders deploying these plugins should treat disclosed vulnerabilities as requiring prompt evaluation and testing, particularly in multi-user or internet-facing WordPress installations; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 98% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Properfraction over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2021
5 years ago
Most Recent CVE
Jun 15, 2026
39 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-34621CRITICAL
A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register
Jul 7, 20219.884NOYES
CVE-2021-34624CRITICAL
A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary
Jul 7, 20219.843NOYES
CVE-2021-34622HIGH
A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate
Jul 7, 20218.841NOYES
CVE-2021-34623CRITICAL
A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrar
Jul 7, 20219.832NONO
CVE-2023-41954HIGH
Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.
May 17, 20248.631NOYES
CVE-2021-24522MEDIUM
The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly
Aug 9, 20216.130NOYES
CVE-2024-9947CRITICAL
The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user
Oct 23, 20249.826NONO
CVE-2026-41556MEDIUM
Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions.
Jun 15, 20266.524NONO
CVE-2022-45083HIGH
Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Conte
Jan 19, 20247.223NONO
CVE-2023-23830MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
May 3, 20236.120NONO
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
75%
11%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network36 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (30.6%)
Unknown0 (0.0%)
Required25 (69.4%)
Privileges Required
Low12 (33.3%)
High11 (30.6%)
None13 (36.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
13.9% of CVEs· 97th percentile
ExploitDB
1 CVE
2.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Properfraction.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Properfraction — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Properfraction's Products

View all 3 CNAs →

Top CWEs