Skip to content

Known CVE

ProfilePress < 3.1.11 - Cross-Site Scripting

The ProfilePress plugin for WordPress before 3.1.11 is vulnerable to unauthenticated reflected cross-site scripting (XSS) via the tabbed login/register widget due to improper escaping of user input. Attackers can inject arbitrary JavaScript via the tabbed-login-name parameter.

CVE-2021-24522

Medium2021CVSS 5.4CWE-79

cve2021 · wordpress · wp · wp-plugin · wp-user-avatar · profilepress · xss · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website