Pricing
Case studies
Login
Start trial
ProfilePress
properfraction
Developer
4.16.8
Latest version
100,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
32 fixed
14 Mitigation rules
Authenticated (Subscriber+) Arbitrary Shortcode Execution vulnerability
<= 4.16.7
Dec 9, 2025
Unauthenticated Arbitrary Shortcode Execution vulnerability
<= 4.16.4
Aug 16, 2025
Admin+ Stored XSS vulnerability
< 4.15.20
Feb 13, 2025
Admin+ Stored XSS vulnerability
< 4.15.15
Dec 12, 2024
Unauthenticated Content Restriction Bypass to Sensitive Information Exposure vulnerability
<= 4.15.18
Nov 26, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget vulnerability
<= 4.15.8
May 23, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.15.4
Apr 15, 2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 4.15.5
Apr 11, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 4.15.2
Mar 12, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode vulnerability
< 4.15.1
Feb 26, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via [reg-select-role] Shortcode vulnerability
<= 4.15.0
Feb 26, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 4.14.4
Feb 20, 2024
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 4.14.4
Feb 20, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode vulnerability
<= 4.14.4
Feb 20, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.14.3
Feb 2, 2024
Broken Access Control vulnerability
<= 4.13.2
Dec 26, 2023
Sensitive Data Exposure via Debug Log vulnerability
<= 4.13.2
Oct 2, 2023
Unauthenticated Limited Privilege Escalation vulnerability
<= 4.13.1
Sep 12, 2023
Broken Access Control vulnerability
<= 4.13.1
Sep 12, 2023
Reflected Cross-Site Scripting via error message vulnerability
< 4.11.0
Jun 26, 2023
Cross Site Scripting (XSS) vulnerability
<= 4.5.4
Feb 21, 2023
Cross Site Scripting (XSS) vulnerability
<= 4.5.4
Feb 20, 2023
Cross Site Scripting (XSS)
<= 4.5.3
Jan 27, 2023
Cross Site Scripting (XSS)
<= 4.5.3
Jan 20, 2023
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
<= 4.5.0
Dec 26, 2022
Authenticated (Administrator+) Stored Cross-Site Scripting via Form Settings vulnerability
<= 4.5.0
Dec 26, 2022
Auth. PHP Object Injection vulnerability
<= 4.3.2
Dec 14, 2022
Unauthenticated Privilege Escalation vulnerability
3.0-3.1.3
Jun 28, 2021
Authenticated Privilege Escalation vulnerability
3.0-3.1.3
Jun 28, 2021
Arbitrary File Upload in Image Uploader Component vulnerability
3.0-3.1.3
Jun 28, 2021
Arbitrary File Upload in File Uploader Component vulnerability
3.0-3.1.3
Jun 28, 2021
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 3.1.7
Jun 28, 2021