properfraction records
35 published records for vendor properfraction.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 42.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-269 Improper Privilege Management3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-862 Missing Authorization2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-502 Deserialization of Untrusted Data1
The weakness classes this vendor ships most often: where to look.
CWEAll records
35 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2021-34621Proof of concept | ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalationproperfraction · profilepress · CWE-269 | Critical9.8 | — | 68.9% | Jul 7, 2021 |
41Plan | CVE-2021-34624Proof of concept | ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Componentproperfraction · profilepress · CWE-434 | Critical9.8 | — | 6.7% | Jul 7, 2021 |
40Plan | CVE-2021-34623No exploit | ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader Componentproperfraction · profilepress · CWE-434 | Critical9.8 | — | 2.1% | Jul 7, 2021 |
39Monitor | CVE-2024-9947No exploit | ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth providerproperfraction · profilepress · CWE-287 | Critical9.8 | — | 0.5% | Oct 23, 2024 |
36Monitor | CVE-2021-34622Proof of concept | ProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalationproperfraction · profilepress · CWE-269 | High8.8 | — | 4.1% | Jul 7, 2021 |
34Monitor | CVE-2023-41954Proof of concept | WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerabilityproperfraction · profilepress · CWE-269 | High8.6 | — | 1.3% | May 17, 2024 |
30Monitor | CVE-2023-44150No exploit | WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposureproperfraction · profilepress · CWE-200 | High7.5 | — | 0.7% | Nov 30, 2023 |
28Monitor | CVE-2022-45083No exploit | WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injectionproperfraction · profilepress · CWE-502 | High7.2 | — | 0.6% | Jan 19, 2024 |
24Monitor | CVE-2021-24522Proof of concept | ProfilePress < 3.1.11 - Unauthenticated Cross-Site Scripting (XSS) in tabbed login/register widgetproperfraction · profilepress · CWE-79 | Medium6.1 | — | 1.6% | Aug 9, 2021 |
24Monitor | CVE-2024-1519No exploit | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-Sproperfraction · profilepress · CWE-79 | Medium6.1 | — | 0.6% | Feb 28, 2024 |
24Monitor | CVE-2023-23830No exploit | WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)properfraction · profilepress · CWE-79 | Medium6.1 | — | 0.4% | May 3, 2023 |
24Monitor | CVE-2022-47444No exploit | WordPress ProfilePress Plugin <= 4.4.1 is vulnerable to Cross Site Scripting (XSS)properfraction · profilepress · CWE-79 | Medium6.1 | — | 0.4% | Mar 29, 2023 |
21Monitor | CVE-2024-1408No exploit | ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcodeproperfraction · profilepress · CWE-79 | Medium5.4 | — | 0.6% | Feb 28, 2024 |
21Monitor | CVE-2024-1535No exploit | ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeproperfraction · profilepress · CWE-79 | Medium5.4 | — | 0.6% | Mar 13, 2024 |
21Monitor | CVE-2024-1806No exploit | ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcodeproperfraction · profilepress · CWE-79 | Medium5.4 | — | 0.6% | Mar 13, 2024 |
21Monitor | CVE-2023-50882No exploit | WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerabilityproperfraction · profilepress · CWE-862 | Medium5.3 | — | 0.5% | Dec 9, 2024 |
21Monitor | CVE-2024-1570No exploit | ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeproperfraction · profilepress · CWE-79 | Medium5.4 | — | 0.5% | Feb 28, 2024 |
21Monitor | CVE-2024-1409No exploit | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) Sproperfraction · profilepress · CWE-79 | Medium5.4 | — | 0.4% | Mar 13, 2024 |
21Monitor | CVE-2024-3210No exploit | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) Sproperfraction · profilepress · CWE-79 | Medium5.4 | — | 0.4% | Apr 10, 2024 |
21Monitor | CVE-2023-41953No exploit | WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerabilityproperfraction · profilepress · CWE-862 | Medium5.3 | — | 0.4% | Dec 9, 2024 |
21Monitor | CVE-2023-23820No exploit | WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)properfraction · profilepress · CWE-79 | Medium5.4 | — | 0.4% | May 3, 2023 |
21Monitor | CVE-2024-11083No exploit | ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposureproperfraction · profilepress · CWE-200 | Medium5.3 | — | 0.4% | Nov 27, 2024 |
21Monitor | CVE-2024-2867No exploit | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) Sproperfraction · profilepress · CWE-20 | Medium5.4 | — | 0.4% | May 2, 2024 |
21Monitor | CVE-2024-1046No exploit | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+) Sproperfraction · profilepress · CWE-79 | Medium5.4 | — | 0.4% | Feb 5, 2024 |
21Monitor | CVE-2024-2861No exploit | ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widgetproperfraction · profilepress · CWE-79 | Medium5.4 | — | 0.3% | May 23, 2024 |
- CVE-2021-3462160This week
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
CriticalCVSS 9.8Proof of conceptEPSS 69%properfraction · profilepressJul 7, 2021
- CVE-2021-3462441Plan
ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Component
CriticalCVSS 9.8Proof of conceptEPSS 7%properfraction · profilepressJul 7, 2021
- CVE-2021-3462340Plan
ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader Component
CriticalCVSS 9.8No exploitEPSS 2%properfraction · profilepressJul 7, 2021
- CVE-2024-994739Monitor
ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider
CriticalCVSS 9.8No exploitEPSS 1%properfraction · profilepressOct 23, 2024
- CVE-2021-3462236Monitor
ProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalation
HighCVSS 8.8Proof of conceptEPSS 4%properfraction · profilepressJul 7, 2021
- CVE-2023-4195434Monitor
WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability
HighCVSS 8.6Proof of conceptEPSS 1%properfraction · profilepressMay 17, 2024
- CVE-2023-4415030Monitor
WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure
HighCVSS 7.5No exploitEPSS 1%properfraction · profilepressNov 30, 2023
- CVE-2022-4508328Monitor
WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection
HighCVSS 7.2No exploitEPSS 1%properfraction · profilepressJan 19, 2024
- CVE-2021-2452224Monitor
ProfilePress < 3.1.11 - Unauthenticated Cross-Site Scripting (XSS) in tabbed login/register widget
MediumCVSS 6.1Proof of conceptEPSS 2%properfraction · profilepressAug 9, 2021
- CVE-2024-151924Monitor
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-S
MediumCVSS 6.1No exploitEPSS 1%properfraction · profilepressFeb 28, 2024
- CVE-2023-2383024Monitor
WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%properfraction · profilepressMay 3, 2023
- CVE-2022-4744424Monitor
WordPress ProfilePress Plugin <= 4.4.1 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%properfraction · profilepressMar 29, 2023
- CVE-2024-140821Monitor
ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode
MediumCVSS 5.4No exploitEPSS 1%properfraction · profilepressFeb 28, 2024
- CVE-2024-153521Monitor
ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 1%properfraction · profilepressMar 13, 2024
- CVE-2024-180621Monitor
ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode
MediumCVSS 5.4No exploitEPSS 1%properfraction · profilepressMar 13, 2024
- CVE-2023-5088221Monitor
WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 1%properfraction · profilepressDec 9, 2024
- CVE-2024-157021Monitor
ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 0%properfraction · profilepressFeb 28, 2024
- CVE-2024-140921Monitor
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) S
MediumCVSS 5.4No exploitEPSS 0%properfraction · profilepressMar 13, 2024
- CVE-2024-321021Monitor
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) S
MediumCVSS 5.4No exploitEPSS 0%properfraction · profilepressApr 10, 2024
- CVE-2023-4195321Monitor
WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%properfraction · profilepressDec 9, 2024
- CVE-2023-2382021Monitor
WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%properfraction · profilepressMay 3, 2023
- CVE-2024-1108321Monitor
ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
MediumCVSS 5.3No exploitEPSS 0%properfraction · profilepressNov 27, 2024
- CVE-2024-286721Monitor
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) S
MediumCVSS 5.4No exploitEPSS 0%properfraction · profilepressMay 2, 2024
- CVE-2024-104621Monitor
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+) S
MediumCVSS 5.4No exploitEPSS 0%properfraction · profilepressFeb 5, 2024
- CVE-2024-286121Monitor
ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget
MediumCVSS 5.4No exploitEPSS 0%properfraction · profilepressMay 23, 2024