SecAlerts
p

profilepress

Security Risk Profile

50
/100
medium

Security Risk Score

Comprehensive risk assessment based on 32 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 16, 2019 to present

32
Total CVEs
6
Critical+High
0
Exploited
5
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
5
Critical/High
Risk Level
50/100
medium
🆕 2Fresh (<7d)📈 5 in Last 30 Days

Severity Distribution

Critical
0
High
6
Medium
26
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
19
2
Code Injection
4
3
Malicious File Upload
1
4
Infoleak
1
5
Input Validation
1

Most Affected Products

1. ProfilePress ProfilePress21
2. properfraction Profilepress Wordpress17
3. ProfilePress Loginwp Wordpress3
4. WordPress ProfilePress2
5. ProfilePress User Registration\, Login Form\, User Profile \& Membership Wordpress2

Recent Vulnerabilities

See more →
CVE-2026-96518
CVSS 5.9medium

WordPress ProfilePress plugin <= 4.17.3 - Broken Access Control vulnerability

Oct 9, 2026🔧 No Patch
CVE-2026-96337
CVSS 6.5medium

WordPress ProfilePress plugin <= 4.17.3 - Broken Access Control vulnerability

Oct 9, 2026🔧 No Patch
CVE-2026-92551
CVSS 6.1medium

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter

Oct 3, 2026🔧 No Patch
CVE-2026-92536
CVSS 8.8high

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields

Oct 3, 2026🔧 No Patch
CVE-2026-85658
CVSS 8.1high

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket)

Sep 19, 2026🔧 No Patch
CVE-2026-19848
CVSS 6.5medium

ProfilePress < 4.17.1 - Unauthenticated Arbitrary Shortcode Execution via Display Name

Aug 21, 2026🔧 No Patch
CVE-2026-13352
CVSS 8.8high

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion

Jul 17, 2026🔧 No Patch
CVE-2026-41556
CVSS 6.5medium

WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability

Jun 15, 2026🔧 No Patch
CVE-2026-3309
CVSS 6.5medium

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing Fields

Apr 4, 2026🔧 No Patch
CVE-2025-8878
CVSS 6.5EPSS 0%medium

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.4 - Unauthenticated Arbitrary Shortcode Execution

Aug 16, 2025🔧 No Patch

Monitor profilepress in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

profilepress Security Vulnerabilities & Risk Score | 32 CVEs | SecAlerts - SecAlerts