VYPR

Wp User Avatar

by WordPress

Source repositories

CVEs (3)

  • CVE-2026-66047HigAug 31, 2026
    risk 0.53cvss 8.1epss 0.01

    ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the…

  • CVE-2026-3309MedApr 4, 2026
    risk 0.42cvss 6.5epss 0.00

    The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.11. This is due to the plugin allowing…

  • CVE-2026-4949MedApr 15, 2026
    risk 0.21cvss 4.3epss 0.00

    The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.16.12. This is due to the 'process_checkout' function…