Properfraction maintains a narrow portfolio of WordPress plugins and access-control extensions that, despite modest product breadth, serve a well-represented niche in the WordPress ecosystem. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a corresponding tendency toward public exploit availability, reflecting the web-application nature of the product line and the appeal of WordPress plugins as attack vectors. The exposure recurs across products such as ProfilePress and Admin Bar & Dashboard Access Control, clustering around cross-site scripting, privilege management, information disclosure, and authorization weaknesses that are characteristic of plugin-based access and user-management functionality. Defenders deploying these plugins should treat disclosed vulnerabilities as requiring prompt evaluation and testing, particularly in multi-user or internet-facing WordPress installations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Properfraction over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34621CRITICAL A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register | Jul 7, 2021 | 9.8 | 84 | NO | YES |
CVE-2021-34624CRITICAL A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary | Jul 7, 2021 | 9.8 | 43 | NO | YES |
CVE-2021-34622HIGH A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate | Jul 7, 2021 | 8.8 | 41 | NO | YES |
CVE-2021-34623CRITICAL A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrar | Jul 7, 2021 | 9.8 | 32 | NO | NO |
CVE-2023-41954HIGH Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1. | May 17, 2024 | 8.6 | 31 | NO | YES |
CVE-2021-24522MEDIUM The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly | Aug 9, 2021 | 6.1 | 30 | NO | YES |
CVE-2024-9947CRITICAL The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user | Oct 23, 2024 | 9.8 | 26 | NO | NO |
CVE-2026-41556MEDIUM Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions. | Jun 15, 2026 | 6.5 | 24 | NO | NO |
CVE-2022-45083HIGH Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Conte | Jan 19, 2024 | 7.2 | 23 | NO | NO |
CVE-2023-23830MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions. | May 3, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Properfraction.
Media articles that mention a CVE ID that affects a product developed by Properfraction — matched by CVE ID, not by vendor name.