Profilepress Membership Team Profilepress vulnerabilities
6 known vulnerabilities affecting profilepress_membership_team/profilepress.
Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2023-50882MEDIUMCVSS 5.3≥ n/a, ≤ 4.13.22024-12-09
CVE-2023-50882 [MEDIUM] CWE-862 CVE-2023-50882: Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress allows Exploiting I
Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.13.2.
nvd
CVE-2023-41953MEDIUMCVSS 5.3≥ n/a, ≤ 4.13.12024-12-09
CVE-2023-41953 [MEDIUM] CWE-862 CVE-2023-41953: Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects
Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1.
nvd
CVE-2023-41954HIGHCVSS 8.6PoC≥ n/a, ≤ 4.13.12024-05-17
CVE-2023-41954 [HIGH] CWE-269 CVE-2023-41954: Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Priv
Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.
nvd
CVE-2023-23820MEDIUMCVSS 5.4≥ n/a, ≤ 4.5.42023-05-03
CVE-2023-23820 [MEDIUM] CWE-79 CVE-2023-23820: Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
nvd
CVE-2023-23830MEDIUMCVSS 6.1≥ n/a, ≤ 4.5.42023-05-03
CVE-2023-23830 [MEDIUM] CWE-79 CVE-2023-23830: Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePr
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
nvd
CVE-2023-23996MEDIUMCVSS 4.8≥ n/a, ≤ 4.5.32023-04-06
CVE-2023-23996 [MEDIUM] CWE-79 CVE-2023-23996: Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Profi
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.3 versions.
nvd