Skip to content
Noroxi

properfraction records

35 published records for vendor properfraction.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
42.9%
Median publish → KEV
No record has entered KEV

All records

35 records
  • CVE-2021-34621
    60This week

    ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation

    CriticalCVSS 9.8Proof of conceptEPSS 69%

    properfraction · profilepressJul 7, 2021

  • ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Component

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    properfraction · profilepressJul 7, 2021

  • ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader Component

    CriticalCVSS 9.8No exploitEPSS 2%

    properfraction · profilepressJul 7, 2021

  • CVE-2024-9947
    39Monitor

    ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider

    CriticalCVSS 9.8No exploitEPSS 1%

    properfraction · profilepressOct 23, 2024

  • ProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalation

    HighCVSS 8.8Proof of conceptEPSS 4%

    properfraction · profilepressJul 7, 2021

  • WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability

    HighCVSS 8.6Proof of conceptEPSS 1%

    properfraction · profilepressMay 17, 2024

  • WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure

    HighCVSS 7.5No exploitEPSS 1%

    properfraction · profilepressNov 30, 2023

  • WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection

    HighCVSS 7.2No exploitEPSS 1%

    properfraction · profilepressJan 19, 2024

  • ProfilePress < 3.1.11 - Unauthenticated Cross-Site Scripting (XSS) in tabbed login/register widget

    MediumCVSS 6.1Proof of conceptEPSS 2%

    properfraction · profilepressAug 9, 2021

  • CVE-2024-1519
    24Monitor

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-S

    MediumCVSS 6.1No exploitEPSS 1%

    properfraction · profilepressFeb 28, 2024

  • WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    properfraction · profilepressMay 3, 2023

  • WordPress ProfilePress Plugin <= 4.4.1 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    properfraction · profilepressMar 29, 2023

  • CVE-2024-1408
    21Monitor

    ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode

    MediumCVSS 5.4No exploitEPSS 1%

    properfraction · profilepressFeb 28, 2024

  • CVE-2024-1535
    21Monitor

    ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    MediumCVSS 5.4No exploitEPSS 1%

    properfraction · profilepressMar 13, 2024

  • CVE-2024-1806
    21Monitor

    ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode

    MediumCVSS 5.4No exploitEPSS 1%

    properfraction · profilepressMar 13, 2024

  • WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 1%

    properfraction · profilepressDec 9, 2024

  • CVE-2024-1570
    21Monitor

    ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    MediumCVSS 5.4No exploitEPSS 0%

    properfraction · profilepressFeb 28, 2024

  • CVE-2024-1409
    21Monitor

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) S

    MediumCVSS 5.4No exploitEPSS 0%

    properfraction · profilepressMar 13, 2024

  • CVE-2024-3210
    21Monitor

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) S

    MediumCVSS 5.4No exploitEPSS 0%

    properfraction · profilepressApr 10, 2024

  • WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    properfraction · profilepressDec 9, 2024

  • WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    properfraction · profilepressMay 3, 2023

  • ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

    MediumCVSS 5.3No exploitEPSS 0%

    properfraction · profilepressNov 27, 2024

  • CVE-2024-2867
    21Monitor

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) S

    MediumCVSS 5.4No exploitEPSS 0%

    properfraction · profilepressMay 2, 2024

  • CVE-2024-1046
    21Monitor

    Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+) S

    MediumCVSS 5.4No exploitEPSS 0%

    properfraction · profilepressFeb 5, 2024

  • CVE-2024-2861
    21Monitor

    ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget

    MediumCVSS 5.4No exploitEPSS 0%

    properfraction · profilepressMay 23, 2024