CVE-2023-44150: WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: from n/a through 4.13.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for the WordPress ProfilePress Plugin vulnerability?
The vulnerability ID for the WordPress ProfilePress Plugin vulnerability is CVE-2023-44150.
What is the severity of the WordPress ProfilePress Plugin vulnerability?
The severity of the WordPress ProfilePress Plugin vulnerability is high with a severity value of 7.5.
What is the affected software for the WordPress ProfilePress Plugin vulnerability?
The affected software for the WordPress ProfilePress Plugin vulnerability is ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.
How can the WordPress ProfilePress Plugin vulnerability be exploited?
The WordPress ProfilePress Plugin vulnerability can be exploited by exposing sensitive information to an unauthorized actor.
Is there a patch or fix available for the WordPress ProfilePress Plugin vulnerability?
Yes, a patch for the WordPress ProfilePress Plugin vulnerability is available. It is recommended to update to version 4.13.3 or higher.