★★★★★★★☆☆☆ 7.1/ 10 - High
A Cross-Site Scripting(XSS) vulnerability was discovered in WordPress ProfilePress Plugin.
Therefore, malicious attackers can inject fraudulent scripts such as redirect, ads, and other HTML payload. This may be executed when guests visit the website.
Update the WordPress ProfilePress Plugin to the newest version (4.5.4 and newer).
We provide information about critical vulnerabilities of WordPress for people who are using or are considering using Wordpress for their projects.
“[WordPress ProfilePress Plugin](versions 4.4.1 and older) Vulnerability in Cross-Site Scripting (XSS)”, by WS Securityis licensed underCC BY 4.0.