Vulnerabilities > Properfraction > Profilepress > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-10-23 CVE-2024-9947 Improper Authentication vulnerability in Properfraction Profilepress
The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1.
network
low complexity
properfraction CWE-287
critical
9.8
2021-07-07 CVE-2021-34624 Unrestricted Upload of File with Dangerous Type vulnerability in Properfraction Profilepress
A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates.
network
low complexity
properfraction CWE-434
critical
9.8
2021-07-07 CVE-2021-34623 Unrestricted Upload of File with Dangerous Type vulnerability in Properfraction Profilepress
A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates.
network
low complexity
properfraction CWE-434
critical
9.8
2021-07-07 CVE-2021-34621 Missing Authentication for Critical Function vulnerability in Properfraction Profilepress
A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator.
network
low complexity
properfraction CWE-306
critical
9.8