• Resolved prosatya

    (@prosatya)


    • WordPress ProfilePress plugin < 4.15.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode vulnerability
    • WordPress ProfilePress plugin <= 4.15.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via [reg-select-role] Shortcode vulnerability
    • WordPress ProfilePress plugin <= 4.14.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
    • WordPress ProfilePress plugin <= 4.14.4 – Unauthenticated Stored Cross-Site Scripting vulnerability
    • WordPress ProfilePress plugin <= 4.14.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode vulnerability
    • WordPress ProfilePress plugin <= 4.14.3 – Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
Viewing 1 replies (of 1 total)
  • Plugin Support Ibrahim Nasir

    (@ibrahimkh4l33l)

    Hello ????

    All these vulnerabilities were reported to us by WordFence and have been patched in our latest release v4.15.2 5 days ago.

    Please update to the latest version.

    Regards

Viewing 1 replies (of 1 total)
  • The topic ‘Site Scan- Critical Issue- Vulnerable Software’ is closed to new replies.