Pricing
Case studies
Login
Start trial
ProfilePress
properfraction
Developer
4.16.12
Latest version
100,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
36 patched
14 Mitigation rules
Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration vulnerability
<= 4.16.11
11/03/2026
Admin+ Stored XSS vulnerability
< 4.15.15
30/01/2026
Admin+ Stored XSS vulnerability
< 4.15.20
31/12/2025
Admin+ Stored XSS vulnerability
< 4.15.20
31/12/2025
Authenticated (Subscriber+) Arbitrary Shortcode Execution vulnerability
<= 4.16.7
09/12/2025
Unauthenticated Arbitrary Shortcode Execution vulnerability
<= 4.16.4
16/08/2025
Admin+ Stored XSS vulnerability
< 4.15.20
13/02/2025
Admin+ Stored XSS vulnerability
< 4.15.15
12/12/2024
Unauthenticated Content Restriction Bypass to Sensitive Information Exposure vulnerability
<= 4.15.18
26/11/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget vulnerability
<= 4.15.8
23/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.15.4
15/04/2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 4.15.5
11/04/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 4.15.2
12/03/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode vulnerability
< 4.15.1
26/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via [reg-select-role] Shortcode vulnerability
<= 4.15.0
26/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 4.14.4
20/02/2024
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 4.14.4
20/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode vulnerability
<= 4.14.4
20/02/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.14.3
02/02/2024
Broken Access Control vulnerability
<= 4.13.2
26/12/2023
Sensitive Data Exposure via Debug Log vulnerability
<= 4.13.2
02/10/2023
Unauthenticated Limited Privilege Escalation vulnerability
<= 4.13.1
12/09/2023
Broken Access Control vulnerability
<= 4.13.1
12/09/2023
Reflected Cross-Site Scripting via error message vulnerability
< 4.11.0
26/06/2023
Cross Site Scripting (XSS) vulnerability
<= 4.5.4
21/02/2023
Cross Site Scripting (XSS) vulnerability
<= 4.5.4
20/02/2023
Cross Site Scripting (XSS)
<= 4.5.3
27/01/2023
Cross Site Scripting (XSS)
<= 4.5.3
20/01/2023
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
<= 4.5.0
26/12/2022
Authenticated (Administrator+) Stored Cross-Site Scripting via Form Settings vulnerability
<= 4.5.0
26/12/2022
Auth. PHP Object Injection vulnerability
<= 4.3.2
14/12/2022
Unauthenticated Privilege Escalation vulnerability
3.0-3.1.3
28/06/2021
Authenticated Privilege Escalation vulnerability
3.0-3.1.3
28/06/2021
Arbitrary File Upload in Image Uploader Component vulnerability
3.0-3.1.3
28/06/2021
Arbitrary File Upload in File Uploader Component vulnerability
3.0-3.1.3
28/06/2021
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 3.1.7
28/06/2021