Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
ProfilePress
properfraction
Developer
4.16.7
Latest version
100,000
Installations
Nov 8, 2025
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Vulnerability history
0 present
31 fixed
13 Mitigation rules
Unauthenticated Arbitrary Shortcode Execution vulnerability
<= 4.16.4
Aug 16, 2025
Admin+ Stored XSS vulnerability
< 4.15.20
Feb 13, 2025
Admin+ Stored XSS vulnerability
< 4.15.15
Dec 12, 2024
Unauthenticated Content Restriction Bypass to Sensitive Information Exposure vulnerability
<= 4.15.18
Nov 26, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget vulnerability
<= 4.15.8
May 23, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.15.4
Apr 15, 2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 4.15.5
Apr 11, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 4.15.2
Mar 12, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode vulnerability
< 4.15.1
Feb 26, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via [reg-select-role] Shortcode vulnerability
<= 4.15.0
Feb 26, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 4.14.4
Feb 20, 2024
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 4.14.4
Feb 20, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode vulnerability
<= 4.14.4
Feb 20, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.14.3
Feb 2, 2024
Broken Access Control vulnerability
<= 4.13.2
Dec 26, 2023
Sensitive Data Exposure via Debug Log vulnerability
<= 4.13.2
Oct 2, 2023
Unauthenticated Limited Privilege Escalation vulnerability
<= 4.13.1
Sep 12, 2023
Broken Access Control vulnerability
<= 4.13.1
Sep 12, 2023
Reflected Cross-Site Scripting via error message vulnerability
< 4.11.0
Jun 26, 2023
Cross Site Scripting (XSS) vulnerability
<= 4.5.4
Feb 21, 2023
Cross Site Scripting (XSS) vulnerability
<= 4.5.4
Feb 20, 2023
Cross Site Scripting (XSS)
<= 4.5.3
Jan 27, 2023
Cross Site Scripting (XSS)
<= 4.5.3
Jan 20, 2023
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
<= 4.5.0
Dec 26, 2022
Authenticated (Administrator+) Stored Cross-Site Scripting via Form Settings vulnerability
<= 4.5.0
Dec 26, 2022
Auth. PHP Object Injection vulnerability
<= 4.3.2
Dec 14, 2022
Unauthenticated Privilege Escalation vulnerability
3.0-3.1.3
Jun 28, 2021
Authenticated Privilege Escalation vulnerability
3.0-3.1.3
Jun 28, 2021
Arbitrary File Upload in Image Uploader Component vulnerability
3.0-3.1.3
Jun 28, 2021
Arbitrary File Upload in File Uploader Component vulnerability
3.0-3.1.3
Jun 28, 2021
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 3.1.7
Jun 28, 2021