Profilepress
36 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Profilepress, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Profilepress CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 1 |
| 2024-12 | 4 |
| 2025-01 | 0 |
| 2025-02 | 3 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 1 |
| 2026-09 | 0 |
Severity
How the 36 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High6
- Medium25
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Profilepress.
- CVE-2026-66047ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE8.1
- CVE-2026-41556WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2024-13120ProfilePress < 4.15.20 - Admin+ Stored XSS4.8
- CVE-2024-13121Paid Membership Plugin < 4.15.20 - Admin+ Stored XSS3.5
- CVE-2024-13119ProfilePress < 4.15.20 - Admin+ Stored XSS4.8
- CVE-2024-10517ProfilePress < 4.15.15 - Admin+ Stored XSS4.8
- CVE-2024-10518ProfilePress < 4.15.15 - Admin+ Stored XSS4.8
- CVE-2023-41953WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability5.3
- CVE-2023-50882WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability5.3
- CVE-2024-11083ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure5.3
- CVE-2024-9947ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider8.1
- CVE-2024-2861ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget6.4
- CVE-2023-41954WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability8.6
- CVE-2024-2867Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
- CVE-2024-3210Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'reg-single-checkbox'6.4
Product grouping is registry-driven, with AI assist and human review. How it works