CVE-2022-47444: WordPress ProfilePress Plugin <= 4.4.1 is vulnerable to Cross Site Scripting (XSS)
Published Mar 29, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin <= 4.5.3 versions.
Affected Software
1 affected component
properfraction Profilepress Wordpress<=4.5.3
Remediation
Information
Update to 4.5.4 or a higher version.
Event History
Mar 29, 2023
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-47444.
2
What is the severity of CVE-2022-47444?
The severity of CVE-2022-47444 is high, with a CVSS score of 6.1.
3
What is the affected software?
The affected software is ProfilePress plugin version 4.5.3 and below.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability through unauthenticated reflected cross-site scripting (XSS).
5
Is there a patch available for this vulnerability?
Yes, a patch is available for this vulnerability. Please refer to the reference URL for more information.