| CVE-2026-92551 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-79
|
6.1
|
Medium
|
2026-10-03 |
| CVE-2026-92536 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-94
|
8.8
|
High
|
2026-10-03 |
| CVE-2026-85658 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket)
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-94
|
8.1
|
High
|
2026-09-19 |
| CVE-2026-3424 |
kk Star Ratings <= 5.4.10.3 - Unauthenticated Arbitrary Shortcode Execution via 'payload' Parameter
— kk Star Ratings – Rate Post & Collect User Feedbacks
CWE-94
|
5.3
|
Medium
|
2026-08-22 |
| CVE-2026-18385 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.19 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-94
|
5.4
|
Medium
|
2026-08-16 |
| CVE-2026-66703 |
WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerability
— MailOptin
CWE-79
|
6.5
|
Medium
|
2026-08-06 |
| CVE-2026-13352 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-434
|
8.8
|
High
|
2026-07-17 |
| CVE-2026-57813 |
WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability
— MailOptin
CWE-266
|
9.8
|
Critical
|
2026-07-13 |
| CVE-2026-59520 |
WordPress CrawlWP SEO plugin <= 3.0.16 - Cross Site Request Forgery (CSRF) vulnerability
— CrawlWP SEO
CWE-352
|
4.3
|
Medium
|
2026-07-05 |
| CVE-2026-41556 |
WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability
— ProfilePress
CWE-79
|
6.5
|
Medium
|
2026-06-15 |
| CVE-2026-4949 |
ProfilePress <= 4.16.12 - Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan Subscription
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-862
|
4.3
|
Medium
|
2026-04-15 |
| CVE-2026-3309 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing Fields
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-94
|
6.5
|
Medium
|
2026-04-04 |
| CVE-2026-3445 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-862
|
7.1
|
High
|
2026-04-04 |
| CVE-2026-3453 |
ProfilePress <= 4.16.11 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-639
|
8.1
|
High
|
2026-03-11 |
| CVE-2025-13642 |
ProfilePress <= 4.16.7 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-94
|
5.4
|
Medium
|
2025-12-09 |
| CVE-2025-58596 |
WordPress MailOptin Plugin <= 1.2.75.0 - Cross Site Scripting (XSS) Vulnerability
— MailOptin
CWE-79
|
5.9
|
Medium
|
2025-09-03 |
| CVE-2025-8878 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.4 - Unauthenticated Arbitrary Shortcode Execution
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-94
|
6.5
|
Medium
|
2025-08-16 |
| CVE-2024-11977 |
kk Star Ratings – Rate Post & Collect User Feedbacks <= 5.4.10 - Unauthenticated Arbitrary Shortcode Execution
— kk Star Ratings – Rate Post & Collect User Feedbacks
CWE-94
|
7.3
|
High
|
2024-12-21 |
| CVE-2024-12309 |
Rate My Post – Star Rating Plugin by FeedbackWP <= 4.2.4 - Unauthenticated Voting On Scheduled Posts
— Rate My Post – Star Rating Plugin by FeedbackWP
CWE-639
|
5.3
|
Medium
|
2024-12-13 |
| CVE-2023-50882 |
WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability
— ProfilePress
CWE-862
|
5.3
|
Medium
|
2024-12-09 |
| CVE-2024-11083 |
ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-200
|
5.3
|
Medium
|
2024-11-27 |
| CVE-2024-8628 |
Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin <= 1.2.70.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
— MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc.
CWE-79
|
5.4
|
Medium
|
2024-09-24 |
| CVE-2024-2861 |
ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-79
|
6.4
|
Medium
|
2024-05-23 |
| CVE-2024-2867 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-20
|
6.4
|
Medium
|
2024-05-02 |
| CVE-2024-3210 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'reg-single-checkbox'
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-79
|
6.4
|
Medium
|
2024-04-10 |
| CVE-2024-1806 |
ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-79
|
6.4
|
Medium
|
2024-03-13 |
| CVE-2024-1409 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via [reg-select-role] Shortcode
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-79
|
6.4
|
Medium
|
2024-03-13 |
| CVE-2024-1535 |
ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-79
|
6.4
|
Medium
|
2024-03-13 |
| CVE-2024-1408 |
ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-79
|
6.4
|
Medium
|
2024-02-20 |
| CVE-2024-1519 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-Site Scripting
— Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
CWE-79
|
6.5
|
Medium
|
2024-02-20 |