The ProfilePress plugin for WordPress before 3.1.11 is vulnerable to unauthenticated reflected cross-site scripting (XSS) via the tabbed login/register widget due to improper escaping of user input. Attackers can inject arbitrary JavaScript via the tabbed-login-name parameter.
id: CVE-2021-24522
info:
name: ProfilePress < 3.1.11 - Cross-Site Scripting
author: ritikchaddh
...