CVE-2024-10517: ProfilePress < 4.15.15 - Admin+ Stored XSS
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Drag & Drop Builder fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10517?
CVE-2024-10517 has a high severity rating due to its potential for Stored Cross-Site Scripting (XSS) attacks by high privilege users.
How do I fix CVE-2024-10517?
To fix CVE-2024-10517, update the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content to version 4.15.15 or later.
Who is affected by CVE-2024-10517?
CVE-2024-10517 affects users of the Paid Membership Plugin on WordPress versions prior to 4.15.15.
What type of vulnerability is CVE-2024-10517?
CVE-2024-10517 is a Stored Cross-Site Scripting (XSS) vulnerability resulting from inadequate sanitization and escaping of user input.
What could happen if CVE-2024-10517 is exploited?
If exploited, CVE-2024-10517 could allow attackers to inject malicious scripts into user profiles, potentially compromising user data.