Profilepress
Vendor:
First CVE: Jul 7, 2021 · Active for 5 years
35
Total CVEs
More Total CVEs than 96% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Profilepress over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2021
5 years ago
Most Recent CVE
Jun 15, 2026
39 days ago
CVE Severity & Scoring
Profilepress35 CVEs
74%
11%
11%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network35 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (31.4%)
Unknown0 (0.0%)
Required24 (68.6%)
Privileges Required
Low12 (34.3%)
High10 (28.6%)
None13 (37.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34621CRITICAL A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register | Jul 7, 2021 | 9.8 | 84 | NO | YES |
CVE-2021-34624CRITICAL A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary | Jul 7, 2021 | 9.8 | 43 | NO | YES |
CVE-2021-34622HIGH A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate | Jul 7, 2021 | 8.8 | 41 | NO | YES |
CVE-2021-34623CRITICAL A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrar | Jul 7, 2021 | 9.8 | 32 | NO | NO |
CVE-2023-41954HIGH Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1. | May 17, 2024 | 8.6 | 31 | NO | YES |
CVE-2021-24522MEDIUM The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly | Aug 9, 2021 | 6.1 | 30 | NO | YES |
CVE-2024-9947CRITICAL The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user | Oct 23, 2024 | 9.8 | 26 | NO | NO |
CVE-2026-41556MEDIUM Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions. | Jun 15, 2026 | 6.5 | 24 | NO | NO |
CVE-2022-45083HIGH Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Conte | Jan 19, 2024 | 7.2 | 23 | NO | NO |
CVE-2023-23830MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions. | May 3, 2023 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (35 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
14.3% of CVEs· 97th percentile
ExploitDB
1 CVE
2.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (35 CVEs).
Media Mentions
Signals from CVEs in this product scope (35 CVEs).
Top CNAs Publishing CVEs For Profilepress
Top CWEs
Versions
No cataloged versions.