WordPress Plugin Vulnerabilities
ProfilePress < 3.1.11 - Multiple Vulnerabilities
Description
The plugin changelog stated multiple vulnerability fixes, including Cross-Site Scripting (XSS), SQL escaping and redirection validation.
The changelog stated:
- Fixed missing sql unescaping in member directory search.
- Validate redirect_to urls to prevent redirect to another site.
- XSS fix by escaping variables in tab widget.
Affects Plugins
References
Miscellaneous
Verified
No
WPVDB ID
Timeline
Publicly Published
2021-07-10 (about 2 years ago)
Added
2021-07-10 (about 2 years ago)
Last Updated
2021-07-10 (about 2 years ago)