Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
wp-user-avatar · плагин
Известные уязвимости для Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress. Узнайте за секунды, какая версия работает на вашем сайте, с WP Lens.
33 известных уязвимостей
1 критичных · без входа эксплуатируется: 11 · 1 с публичным эксплойтом · последняя 19 сент. 2026 г.
Опубликован на wordpress.org · последняя версия 4.17.6 · обновлён 2 окт. 2026 г. · 100 тыс.+ установок
статус на wordpress.org проверен 2 окт. 2026 г.
Уязвимости
- Критич. 9.2
CVE-2026-66047без авторизации→ 4.17.2
ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE
- Высокий 8.8
CVE-2026-13352автор+≤ 4.16.18
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File
- Высокий 8.6
CVE-2023-41954без авторизации≤ 4.13.1
WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability
- Высокий 8.1
CVE-2026-85658подписчик+≤ 4.17.2
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortco
- Высокий 8.1
CVE-2026-3453подписчик+≤ 4.16.11
ProfilePress <= 4.16.11 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration
- Высокий 7.5
CVE-2023-44150без авторизации≤ 4.13.2
WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure
- Высокий 7.2
CVE-2022-45083высокие права≤ 4.3.2
WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection
- Высокий 7.1
CVE-2026-3445подписчик+≤ 4.16.11
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Missing Authorization to Auth
- Средний 6.5
CVE-2026-3309без авторизации≤ 4.16.11
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Sho
- Средний 6.5
CVE-2025-8878без авторизации≤ 4.16.4
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.4 - Unauthenticated Arbitrary Sho
- Средний 6.5
CVE-2026-41556подписчик+≤ 4.16.13
WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability
- Средний 6.1
CVE-2024-1519без авторизации≤ 4.14.4
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-S
- Средний 6.1
CVE-2023-23830без авторизации · нужен клик≤ 4.5.4
WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)
- Средний 6.1
CVE-2022-47444без авторизации · нужен клик≤ 4.5.3
WordPress ProfilePress Plugin <= 4.4.1 is vulnerable to Cross Site Scripting (XSS)
- Средний 5.4
CVE-2026-18385подписчик+≤ 4.16.19
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.19 - Authenticated (Subscriber+) Arbitrary Shortc
- Средний 5.4
CVE-2025-13642подписчик+≤ 4.16.7
ProfilePress <= 4.16.7 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
- Средний 5.4
CVE-2024-2861участник+≤ 4.15.8
ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget
- Средний 5.4
CVE-2024-2867участник+≤ 4.15.4
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) S
- Средний 5.4
CVE-2024-3210участник+≤ 4.15.5
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) S
- Средний 5.4
CVE-2024-1806участник+≤ 4.15.1
ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode
- Средний 5.4
CVE-2024-1535участник+≤ 4.15.2
ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- Средний 5.4
CVE-2024-1409участник+≤ 4.15.0
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) S
- Средний 5.4
CVE-2024-1570участник+≤ 4.14.4
ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- Средний 5.4
CVE-2024-1408участник+≤ 4.14.4
ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode
- Средний 5.4
CVE-2024-1046участник+≤ 4.14.3
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+) S
- Средний 5.4
CVE-2023-23820участник+≤ 4.5.4
WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)
- Средний 5.3
CVE-2023-41953без авторизации≤ 4.13.1
WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability
- Средний 5.3
CVE-2023-50882без авторизации≤ 4.13.2
WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability
- Средний 5.3
CVE-2024-11083без авторизации≤ 4.15.18
ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
- Средний 4.8
CVE-2023-23996админ≤ 4.5.3
WordPress ProfilePress Plugin <= 4.5.3 is vulnerable to Cross Site Scripting (XSS)
- Средний 4.8
CVE-2022-4698админ≤ 4.5.0
ProfilePress <= 4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Form Settings
- Средний 4.8
CVE-2022-4697админ≤ 4.5.0
ProfilePress <= 4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
- Средний 4.3
CVE-2026-4949подписчик+≤ 4.16.12
ProfilePress <= 4.16.12 - Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan Subscription
Метка доступа берётся из текста самой записи (напр. «подписчик+»: подписчик и выше). Если роль не названа, по CVSS указывается «нужен вход» или «высокие права»; роль не выдумывается. «Нужен клик»: атака зависит от того, что авторизованный пользователь перейдёт по ссылке (CSRF, отражённый XSS).