VYPR

User Registration, Login Form, User Profile & Membership

by WordPress

CVEs (4)

  • CVE-2021-24955MedDec 13, 2021
    risk 0.40cvss 6.1epss 0.01

    The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

  • CVE-2021-24954MedDec 13, 2021
    risk 0.40cvss 6.1epss 0.01

    The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue

  • CVE-2021-24522MedAug 9, 2021
    risk 0.40cvss 6.1epss 0.02

    The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the…

  • CVE-2021-24450MedAug 2, 2021
    risk 0.31cvss 4.8epss 0.01

    The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 did not sanitise or escape some of its settings before saving them and outputting them back in the page, allowing high privilege users such as admin…