Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

Vulnerabilities 48Slug wp-user-avatarLatest version 4.16.15WordPress.org →

Minimum safe version

4.16.14

Update to 4.16.14 or later to address 44 fixable vulnerabilities

Latest available4.16.15 Affected up to3.1.3
N/A
2026-04-23< 4.16.14

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting

N/A
2026-03-10< 4.16.12

ProfilePress <= 4.16.11 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration

N/A
2026-04-03< 4.16.12

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing Fields

N/A
2026-04-03< 4.16.12

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass

Medium 6.5
2025-08-16< 4.16.5

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.4 - Unauthenticated Arbitrary Shortcode Execution

Medium 4.8
2024-12-12< 4.15.15

CVE-2024-10518

Medium 5.3
2024-12-26< 4.13.3

WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Broken Access Control

N/A
2023-09-09< 4.13.2

ProfilePress <= 4.13.1 Cross-Site Request Forgery via 'admin_notice'

N/A
2023-09-09< 4.13.2

ProfilePress <= 4.13.1 - Limited Privilege Escalation via 'acceptable_defined_roles'

N/A
< 3.1.11

ProfilePress &lt; 3.1.11 - Multiple Vulnerabilities

N/A
2023-06-26< 4.11.0

WordPress ProfilePress Plugin < 4.11.0 is vulnerable to Cross Site Scripting (XSS)

N/A
2023-06-23< 4.11.0

ProfilePress <= 4.10.3 - Reflected Cross-Site Scripting via error message

Medium 4.8
2022-12-26< 4.5.1

WordPress ProfilePress Plugin <= 4.5.0 is vulnerable to Cross Site Scripting (XSS)

Medium 4.8
2022-12-26< 4.5.1

WordPress ProfilePress Plugin <= 4.5.0 is vulnerable to Cross Site Scripting (XSS)

N/A
2022-07-22< 3.2.16

WordPress Membership, User Registration, Login Form, User Profile & Restrict Content Plugin – ProfilePress <= 3.2.15 - Reflected Cross-Site Scripting