Cross-Site Scripting
28 records62.2%First: 2021. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 45 vulnerability records associated with Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress, published between 2021 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2021 | 8 | |
| 2022 | 4 | |
| 2023 | 8 | |
| 2024 | 13 | |
| 2025 | 5 | |
| 2026 | 7 |
| Severity | Records | Share |
|---|---|---|
| Critical | 5 | 11.1% |
| High | 7 | 15.6% |
| Medium | 33 | 73.3% |
First: 2021. Latest: 2026.
First: 2021. Latest: 2026.
First: 2022. Latest: 2026.
First: 2021. Latest: 2026.
First: 2026. Latest: 2026.
First: 2023. Latest: 2024.
First: 2023. Latest: 2023.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.16.194.16.184.16.144.16.134.16.124.16.84.16.54.15.204.15.194.15.154.15.94.15.54.15.64.15.34.15.24.15.14.15.04.14.44.13.34.13.24.11.04.5.54.5.44.5.14.4.03.2.163.2.33.1.113.1.43.1.8Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-4.13.2 | ProfilePress <= 4.13.2 - Information Disclosure via Debug Log | October 2, 2023 | 4.13.3 | Medium |
[*, 4.13.2) | ProfilePress <= 4.13.1 Cross-Site Request Forgery via 'admin_notice' | September 9, 2023 | 4.13.2 | Medium |
[*, 4.13.2) | ProfilePress <= 4.13.1 - Limited Privilege Escalation via 'acceptable_defined_roles' | September 9, 2023 | 4.13.2 | High |
[*, 4.11.0) | ProfilePress <= 4.10.3 - Reflected Cross-Site Scripting via error message | June 23, 2023 | 4.11.0 | Medium |
*-4.5.3 | ProfilePress <= 4.5.3 - Unauthenticated Cross-Site Scripting | March 27, 2023 | 4.5.4 | High |
*-4.5.4 | ProfilePress <= 4.5.4 - Unauthenticated Stored Cross-Site Scripting | February 21, 2023 | 4.5.5 | High |
*-4.5.4 | ProfilePress <= 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes | February 20, 2023 | 4.5.5 | Medium |
*-4.5.3 | ProfilePress <= 4.5.3 - Authenticated (Administrator+) Stored Cross-Site Scripting | January 20, 2023 | 4.5.4 | Medium |
*-4.5.0 | ProfilePress <= 4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Form Settings | December 23, 2022 | 4.5.1 | Medium |
*-4.5.0 | ProfilePress <= 4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting | December 23, 2022 | 4.5.1 | Medium |
*-4.3.2 | ProfilePress <= 4.3.2 - Authenticated (Admin+) PHP Object Injection | December 14, 2022 | 4.4.0 | Medium |
*-3.2.15 | WordPress Membership, User Registration, Login Form, User Profile & Restrict Content Plugin – ProfilePress <= 3.2.15 - Reflected Cross-Site Scripting | July 22, 2022 | 3.2.16 | Medium |
[*, 3.2.3) | ProfilePress <= 3.2.2 - Reflected Cross-Site Scripting via ppress_cc_data Parameter | November 15, 2021 | 3.2.3 | Medium |
[*, 3.2.3) | ProfilePress <= 3.2.2 - Reflected Cross-Site Scripting | November 15, 2021 | 3.2.3 | Medium |
*-3.1.10 | Paid Membership, User Registration, User Profile & Restrict Content Plugin – ProfilePress <= 3.1.10 - Unauthenticated Cross-Site Scripting | August 9, 2021 | 3.1.11 | High |
3.0.0-3.1.3 | ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation | June 28, 2021 | 3.1.4 | Critical |
3.0.0-3.1.3 | ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload | June 28, 2021 | 3.1.4 | Critical |
3.0.0-3.1.3 | User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) 3.0.0 - 3.1.3 - Unauthenticated Privilege Escalation | June 28, 2021 | 3.1.4 | Critical |
3.0.0-3.1.3 | User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) 3.0.0 - 3.1.3 - Unauthenticated Privilege Escalation | June 28, 2021 | 3.1.4 | Critical |
[*, 3.1.8) | ProfilePress <= 3.1.7 - Authenticated Stored Cross-Site Scripting | June 28, 2021 | 3.1.8 | Medium |
Selected source records
Published: July 16, 2026
Published: July 3, 2026
Published: April 23, 2026
Published: April 15, 2026
Published: April 3, 2026
Published: April 3, 2026
Published: March 10, 2026
Published: December 8, 2025
Published: June 28, 2021
Published: June 28, 2021
Published: June 28, 2021
Published: June 28, 2021
Published: July 3, 2026
Published: July 16, 2026
Published: March 10, 2026
Published: September 9, 2023
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.