PT-2021-16044 · WordPress · Profilepress
Stiofan
·
Published
2021-08-09
·
Updated
2025-06-05
·
CVE-2021-24522
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) versions prior to 3.1.11
Description
The issue concerns a lack of proper escaping in the widget for tabbed login/register, which could be exploited in a cross-site scripting (XSS) attack. This attack could potentially lead to access to the wp-admin section. Additionally, the plugin incorrectly assigned
$ POST as $ GET in several places, allowing the issue to be replicated using only $ GET parameters without the need for $ POST values.Recommendations
For versions prior to 3.1.11, update to version 3.1.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the tabbed login/register widget until the update is applied. Avoid using the
$ POST and $ GET parameters interchangeably in the plugin's configuration to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Profilepress