CVE Database
/

CVE-2021-24522

Back to search

CVE-2021-24522

Published: Aug 9, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as $_GET which meant that in some cases this could be replicated with just $_GET parameters and no need for $_POST values.

VendorProductVersions

Unknown

User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar)

affected
3.1.11 - < 3.1.11

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now