Profilepress

Vendor:

First CVE: Jul 7, 2021 · Active for 5 years

35
Total CVEs
More Total CVEs than 96% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Profilepress over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2021
5 years ago
Most Recent CVE
Jun 15, 2026
39 days ago

CVE Severity & Scoring

Profilepress35 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network35 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (31.4%)
Unknown0 (0.0%)
Required24 (68.6%)
Privileges Required
Low12 (34.3%)
High10 (28.6%)
None13 (37.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register
Jul 7, 20219.884NOYES
A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary
Jul 7, 20219.843NOYES
A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate
Jul 7, 20218.841NOYES
A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrar
Jul 7, 20219.832NONO
Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.
May 17, 20248.631NOYES
The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly
Aug 9, 20216.130NOYES
The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user
Oct 23, 20249.826NONO
Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions.
Jun 15, 20266.524NONO
Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Conte
Jan 19, 20247.223NONO
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
May 3, 20236.120NONO

Exploit Exposure

Signals from CVEs in this product scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
14.3% of CVEs· 97th percentile
ExploitDB
1 CVE
2.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (35 CVEs).

Media Mentions

Signals from CVEs in this product scope (35 CVEs).

Top CNAs Publishing CVEs For Profilepress

Top CWEs

Versions

No cataloged versions.