Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Minimum safe version
4.16.14
Update to 4.16.14 or later to address 44 fixable vulnerabilities
CVE-2026-4949
ProfilePress <= 4.16.11 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing Fields
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass
CVE-2025-13642
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.4 - Unauthenticated Arbitrary Shortcode Execution
CVE-2024-13121
CVE-2024-13119
CVE-2024-13120
CVE-2024-10518
CVE-2024-10517
CVE-2024-11083
CVE-2024-2861
CVE-2024-2867
CVE-2024-3210
CVE-2024-1535
CVE-2024-1409
CVE-2024-1806
CVE-2024-1519
CVE-2024-1570
CVE-2024-1408
CVE-2024-1046
WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Broken Access Control
CVE-2023-44150
CVE-2023-41954
CVE-2023-41953
ProfilePress <= 4.13.1 Cross-Site Request Forgery via 'admin_notice'
ProfilePress <= 4.13.1 - Limited Privilege Escalation via 'acceptable_defined_roles'
ProfilePress < 3.1.11 - Multiple Vulnerabilities
WordPress ProfilePress Plugin < 4.11.0 is vulnerable to Cross Site Scripting (XSS)
ProfilePress <= 4.10.3 - Reflected Cross-Site Scripting via error message
CVE-2023-23830
CVE-2023-23820
CVE-2022-47444
CVE-2023-23996
WordPress ProfilePress Plugin <= 4.5.0 is vulnerable to Cross Site Scripting (XSS)
WordPress ProfilePress Plugin <= 4.5.0 is vulnerable to Cross Site Scripting (XSS)
WordPress Membership, User Registration, Login Form, User Profile & Restrict Content Plugin – ProfilePress <= 3.2.15 - Reflected Cross-Site Scripting
CVE-2022-45083
CVE-2021-34624
CVE-2021-34623
CVE-2021-34622
CVE-2021-34621
CVE-2021-24450
CVE-2021-24522
CVE-2021-24955
CVE-2021-24954