CVE-2024-1409: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via [reg-select-role] Shortcode
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [reg-select-role] shortcode in all versions up to, and including, 4.15.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1409?
CVE-2024-1409 is classified with a medium severity due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-1409?
To fix CVE-2024-1409, update the Paid Membership Plugin for WordPress to version 4.15.1 or later.
Who is affected by CVE-2024-1409?
All users of the ProfilePress plugin for WordPress running versions up to and including 4.15.0 are affected by CVE-2024-1409.
What kind of attack does CVE-2024-1409 enable?
CVE-2024-1409 enables stored cross-site scripting (XSS) attacks via the reg-select-role shortcode.
Is there a workaround for CVE-2024-1409?
There are no official workarounds for CVE-2024-1409, so it is recommended to update the plugin promptly.