Known Vulnerabilities for ProfilePress by Unknown
Listed below are 5 of the newest known vulnerabilities associated with "ProfilePress" by "Unknown".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66047 json | ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability ... | Not Provided | 2026-08-31 | 2026-09-02 |
| CVE-2026-41556 json | Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-19848 json | The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering the... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-18385 json | The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePre... | Not Provided | 2026-08-16 | 2026-08-17 |
| CVE-2026-13352 json | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress p... | Not Provided | 2026-07-17 | 2026-07-17 |